ExamGecko
Question list
Search
Search

Question 66 - CISM discussion

Report
Export

An information security manager finds that a soon-to-be deployed online application will increase risk beyond acceptable levels, and necessary controls have not been included. Which of the following is the BEST course of action for the information security manager?

A.
Instruct IT to deploy controls based on urgent business needs.
Answers
A.
Instruct IT to deploy controls based on urgent business needs.
B.
Present a business case for additional controls to senior management.
Answers
B.
Present a business case for additional controls to senior management.
C.
Solicit bids for compensating control products.
Answers
C.
Solicit bids for compensating control products.
D.
Recommend a different application.
Answers
D.
Recommend a different application.
Suggested answer: B

Explanation:

The information security manager should present a business case for additional controls to senior management, as this is the most effective way to communicate the risk and the need for mitigation. The information security manager should not instruct IT to deploy controls based on urgent business needs, as this may not align with the business objectives and may cause unnecessary costs and delays. The information security manager should not solicit bids for compensating control products, as this may not address the root cause of the risk and may not be the best solution.The information security manager should not recommend a different application, as this may not be feasible or desirable for the business.Reference= CISM Review Manual 2023, page 711; CISM Review Questions, Answers & Explanations Manual 2023, page 252

asked 01/10/2024
Abbas Ali
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first