ExamGecko
Question list
Search
Search

Question 74 - CISM discussion

Report
Export

An information security manager learns that IT personnel are not adhering to the information security policy because it creates process inefficiencies. What should the information security manager do FIRST?

A.
Conduct user awareness training within the IT function.
Answers
A.
Conduct user awareness training within the IT function.
B.
Propose that IT update information security policies and procedures.
Answers
B.
Propose that IT update information security policies and procedures.
C.
Determine the risk related to noncompliance with the policy.
Answers
C.
Determine the risk related to noncompliance with the policy.
D.
Request that internal audit conduct a review of the policy development process,
Answers
D.
Request that internal audit conduct a review of the policy development process,
Suggested answer: C

Explanation:

The information security manager should first determine the risk related to noncompliance with the policy, as this will help to understand the impact and likelihood of the policy violation and the potential consequences for the organization. The information security manager can then use the risk assessment results to communicate the importance of the policy to the IT personnel, propose any necessary changes to the policy or the processes, or request an audit of the policy development process, depending on the situation. Conducting user awareness training, updating policies and procedures, or requesting an audit are possible actions that the information security manager can take after determining the risk, but they are not the first step.Reference= CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Assessment, page 86; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 59, page 60.

asked 01/10/2024
Flora Hundal
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first