| Exam Code/Number: | ISMPJoin the discussion |
| Exam Name: | Information Security Management Professional based on ISO/IEC 27001 |
| Certification: | EXIN |
| Question Number: | 31 |
| Publish Date: | Jul 26, 2026 |
|
Rating
100%
|
|
What is the best way to start setting the information security controls?
An information security officer is asked to write a retention policy for a financial system. She is aware of the fact that some data must be kept for a long time and other data must be deleted.
Where should she look for guidelines first?
Zoning is a security control to separate physical areas with different security levels. Zones with higher security levels can be secured by more controls. The facility manager of a conference center is responsible for security.
What combination of business functions should be combined into one security zone?
An employee has worked on the organizational risk assessment. The goal of the assessment is not to bring residual risks to zero, but to bring the residual risks in line with an organization's risk appetite.
When has the risk assessment program accomplished its primary goal?
A security architect argues with the internal fire prevention team about the statement in the information security policy, that doors to confidential areas should be locked at all times. The emergency response team wants to access to those areas in case of fire.
What is the best solution to this dilemma?