ExamGecko
Question list
Search
Search

Question 382 - CISM discussion

Report
Export

An organization has purchased an Internet sales company to extend the sales department. The information security manager's FIRST step to ensure the security policy framework encompasses the new business model is to:

A.
perform a gap analysis.
Answers
A.
perform a gap analysis.
B.
implement both companies' policies separately
Answers
B.
implement both companies' policies separately
C.
merge both companies' policies
Answers
C.
merge both companies' policies
D.
perform a vulnerability assessment
Answers
D.
perform a vulnerability assessment
Suggested answer: A

Explanation:

Performing a gap analysis is the first step to ensure the security policy framework encompasses the new business model because it is a process of comparing the current state of security policies and controls with the desired or required state. A gap analysis helps to identify the strengths and weaknesses of the existing security policy framework, as well as the opportunities and threats posed by the new business model. A gap analysis also helps to prioritize the actions and resources needed to close the gaps and align the security policy framework with the new business objectives and requirements. Therefore, performing a gap analysis is the correct answer.

https://secureframe.com/blog/security-frameworks

https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one

asked 01/10/2024
Faqeer Ali
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first