ExamGecko
Question list
Search
Search

Question 507 - CISM discussion

Report
Export

An organization uses a security standard that has undergone a major revision by the certifying authority. The old version of the standard will no longer be used for organizations wishing to maintain their certifications. Which of the following should be the FIRST

course of action?

A.
Evaluate the cost of maintaining the certification.
Answers
A.
Evaluate the cost of maintaining the certification.
B.
Review the new standard for applicability to the business.
Answers
B.
Review the new standard for applicability to the business.
C.
Modify policies to ensure new requirements are covered.
Answers
C.
Modify policies to ensure new requirements are covered.
D.
Communicate the new standard to senior leadership.
Answers
D.
Communicate the new standard to senior leadership.
Suggested answer: B

Explanation:

Reviewing the new standard for applicability to the business is the first course of action, as it helps to understand the changes, gaps, and impacts of the revision on the organization's security posture, compliance status, and business objectives. Evaluating the cost of maintaining the certification, modifying policies to ensure new requirements are covered, and communicating the new standard to senior leadership are important steps, but they should be done after reviewing the new standard for applicability to the business.

Reference= CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.2

asked 01/10/2024
Daniel Martos
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first