ExamGecko
Question list
Search
Search

Question 466 - CISM discussion

Report
Export

Internal audit has reported a number of information security issues that are not in compliance with regulatory requirements. What should the information security manager do FIRST?

A.
Perform a vulnerability assessment
Answers
A.
Perform a vulnerability assessment
B.
Perform a gap analysis to determine needed resources
Answers
B.
Perform a gap analysis to determine needed resources
C.
Create a security exception
Answers
C.
Create a security exception
D.
Assess the risk to business operations
Answers
D.
Assess the risk to business operations
Suggested answer: D

Explanation:

According to the CISM Manual, the information security manager should first assess the risk to business operations before taking any other action. This will help to prioritize the issues and determine the appropriate response.Performing a vulnerability assessment, a gap analysis, or creating a security exception are possible actions, but they should be based on the risk assessment results.Reference= CISM Manual, 5th Edition, page 1211; CISM Practice Quiz, question 32

asked 01/10/2024
Aldrin Plata
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first