ExamGecko
Question list
Search
Search

Question 430 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST after discovering that a business unit has implemented a newly purchased application and bypassed the change management process?

A.
Revise the procurement process.
Answers
A.
Revise the procurement process.
B.
Update the change management process.
Answers
B.
Update the change management process.
C.
Discuss the issue with senior leadership.
Answers
C.
Discuss the issue with senior leadership.
D.
Remove the application from production.
Answers
D.
Remove the application from production.
Suggested answer: C

Explanation:

An information security manager should first discuss the issue with senior leadership to escalate the problem and seek their support and guidance. Bypassing the change management process can introduce significant risks to the organization, such as unauthorized access, data loss, system instability, or compliance violations. The information security manager should explain the potential impact and consequences of the incident, and recommend corrective actions to remediate the situation. The information security manager should also review the root cause of the incident and identify any gaps or weaknesses in the existing policies, procedures, or controls that allowed the business unit to implement the new application without proper authorization, testing, or documentation. The information security manager should then revise the procurement process, update the change management process, or implement other measures to prevent similar incidents from occurring in the future.Removing the application from production may not be feasible or desirable, depending on the business needs and the severity of the risks involved.References= CISM Review Manual, 16th Edition, pages 100-1011; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 2692

Learn more:

1. isaca.org2. amazon.com3. gov.uk

asked 01/10/2024
James Morris
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first