ExamGecko
Question list
Search
Search

Question 373 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST after a new cybersecunty regulation has been introduced?

A.
Conduct a cost-benefit analysis.
Answers
A.
Conduct a cost-benefit analysis.
B.
Consult corporate legal counsel
Answers
B.
Consult corporate legal counsel
C.
Update the information security policy.
Answers
C.
Update the information security policy.
D.
Perform a gap analysis.
Answers
D.
Perform a gap analysis.
Suggested answer: D

Explanation:

When a new cybersecurity regulation has been introduced, an information security manager should first consult corporate legal counsel to understand the scope, applicability, and implications of the regulation for the organization. Legal counsel can also advise on the compliance obligations and deadlines, as well as the potential penalties or sanctions for non-compliance. Based on this information, the information security manager can then perform a gap analysis to assess the current state of compliance and identify any areas that need improvement. The information security policy can then be updated accordingly to reflect the new regulatory requirements.

Reference: https://www.isaca.org/credentialing/cism https://www.wiley.com/en-us/CISM+Certified+Information+Security+Manager+Study+Guide-p-9781119801948

asked 01/10/2024
Juan Carlos Delgado
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first