Isaca Certified Information Security Manager CISM Question # 176 Topic 18 Discussion

Isaca Certified Information Security Manager CISM Question # 176 Topic 18 Discussion

CISM Exam Topic 18 Question 176 Discussion:
Question #: 176
Topic #: 18

Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?


A.

Security policy


B.

Risk management framework


C.

Risk appetite


D.

Security standards


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.