ExamGecko
Question list
Search
Search

Question 240 - CISM discussion

Report
Export

A multinational organization is required to follow governmental regulations with different security requirements at each of its operating locations. The chief information security officer (CISO) should be MOST concerned with:

A.
developing a security program that meets global and regional requirements.
Answers
A.
developing a security program that meets global and regional requirements.
B.
ensuring effective communication with local regulatory bodies.
Answers
B.
ensuring effective communication with local regulatory bodies.
C.
using industry best practice to meet local legal regulatory requirements.
Answers
C.
using industry best practice to meet local legal regulatory requirements.
D.
monitoring compliance with defined security policies and standards.
Answers
D.
monitoring compliance with defined security policies and standards.
Suggested answer: A

Explanation:

= A multinational organization is required to follow governmental regulations with different security requirements at each of its operating locations. This means that the CISO has to deal with multiple and diverse legal, regulatory, and compliance issues across different jurisdictions and markets. The CISO should be most concerned with developing a security program that meets global and regional requirements, such as ISO/IEC 27001, NIST CSF, PCI DSS, GDPR, etc. These standards provide a framework for establishing, implementing, maintaining, and improving an information security management system (ISMS) that aligns with the organization's business objectives and risk appetite. The CISO should also ensure that the security program is consistent and coherent across all operating locations, and that it complies with the specific regulations of each location. Therefore, option A is the most appropriate answer.Reference= CISM Review Manual 15th Edition, page 255; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 234. In this scenario, the chief information security officer (CISO) should be most concerned with developing a security program that meets the global and regional requirements of the organization. This includes considering the different legal and regulatory requirements of each operating location, and designing a security program that meets all of these requirements. The CISO should also ensure effective communication with local regulatory bodies to ensure compliance and understanding of the security program. Additionally, the CISO should use industry best practices and defined security policies and standards to ensure the program meets all applicable requirements.

asked 01/10/2024
Silfredo Jimenez Munoz
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first