ExamGecko
Question list
Search
Search

Question 464 - CISM discussion

Report
Export

A new regulatory requirement affecting an organization's information security program is released. Which of the following should be the information security manager's FIRST course of action?

A.
Perform a gap analysis.
Answers
A.
Perform a gap analysis.
B.
Conduct benchmarking.
Answers
B.
Conduct benchmarking.
C.
Notify the legal department.
Answers
C.
Notify the legal department.
D.
Determine the disruption to the business.
Answers
D.
Determine the disruption to the business.
Suggested answer: C

Explanation:

= A new regulatory requirement affecting an organization's information security program is released. The information security manager's first course of action should be to notify the legal department, as they are responsible for ensuring compliance with the relevant laws and regulations.The legal department can advise the information security manager on how to interpret and implement the new requirement, as well as what are the potential implications and risks for the organization12.

References=1: CISM Review Manual (Digital Version), page 2712: CISM Review Manual (Print Version), page 271

Learn more:

1. isaca.org2. csoonline.com

asked 01/10/2024
Tamas Szekely
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first