試験科目:「Certified Information Security Manager」

NO.1 Security technologies should be selected PRIMARILY on the basis of their:
A. use of new and emerging technologies.
B. ability to mitigate business risks.
C. evaluations in trade publications.
D. benefits in comparison to their costs.
Answer: B

The most fundamental evaluation criterion for the appropriate selection of any security technology
is its ability to reduce or eliminate business risks. Investments in security technologies should be
based on their overall value in relation to their cost; the value can be demonstrated in terms of risk
mitigation. This should take precedence over whether they use new or exotic technologies or how
they are evaluated in trade publications.

NO.2 It is MOST important that information security architecture be aligned with which of the
A. Information security best practices
B. Industry best practices
C. Business objectives and goals
D. Information technology plans
Answer: C

Information security architecture should always be properly aligned with business goals and
objectives. Alignment with IT plans or industry and security best practices is secondary by

NO.3 Which of the following represents the MAJOR focus of privacy regulations?
A. Identity theft
B. Unrestricted data mining
C. Identifiable personal data
D. Human rights protection D.
Answer: C

Protection of identifiable personal data is the major focus of recent privacy regulations such as the
Health Insurance Portability and Accountability Act (HIPAA). Data mining is an accepted tool for ad
hoc reporting; it could pose a threat to privacy only if it violates regulator)' provisions. Identity theft
is a potential consequence of privacy violations but not the main focus of many regulations. Human
rights addresses privacy issues but is not the main focus of regulations.

NO.4 The MOST important component of a privacy policy is:
A. geographic coverage.
B. notifications.
C. warranties.
D. liabilities.
Answer: B
Privacy policies must contain notifications and opt-out provisions: they are a high-level
management statement of direction. They do not necessarily address warranties, liabilities or
geographic coverage, which are more specific.

