ExamGecko
Question list
Search
Search

Question 258 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?

A.
Revisit the business objective.
Answers
A.
Revisit the business objective.
B.
Escalate to senior management.
Answers
B.
Escalate to senior management.
C.
Perform a cost-benefit analysis.
Answers
C.
Perform a cost-benefit analysis.
D.
Recommend risk acceptance.
Answers
D.
Recommend risk acceptance.
Suggested answer: B

Explanation:

Escalate to senior management, because this could help the information security manager to inform the decision-makers of the situation, explain the implications and trade-offs, and seek their guidance and approval for the next steps2. However, this answer is not certain, and you might need to consider other factors as well.

asked 01/10/2024
Echo Wind
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first