ExamGecko
Question list
Search
Search

Question 281 - CISM discussion

Report
Export

Which of the following should be an information security manager's FIRST course of action when a newly introduced privacy regulation affects the business?

A.
Consult with IT staff and assess the risk based on their recommendations
Answers
A.
Consult with IT staff and assess the risk based on their recommendations
B.
Update the security policy based on the regulatory requirements
Answers
B.
Update the security policy based on the regulatory requirements
C.
Propose relevant controls to ensure the business complies with the regulation
Answers
C.
Propose relevant controls to ensure the business complies with the regulation
D.
Identify and assess the risk in the context of business objectives
Answers
D.
Identify and assess the risk in the context of business objectives
Suggested answer: D

Explanation:

Identify and assess the risk in the context of business objectives. Before making any changes to the security policy or introducing any new controls, the information security manager should first identify and assess the risk that the new privacy regulation poses to the business. This should be done in the context of the overall business objectives so that the security measures introduced are tailored to meet the specific needs of the organization.

asked 01/10/2024
Ramzi Smair
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first