ExamGecko
Question list
Search
Search

Question 520 - CISM discussion

Report
Export

The information security manager of a multinational organization has been asked to consolidate the information security policies of its regional locations. Which of the following would be of

GREATEST concern?

A.
Varying threat environments
Answers
A.
Varying threat environments
B.
Disparate reporting lines
Answers
B.
Disparate reporting lines
C.
Conflicting legal requirements
Answers
C.
Conflicting legal requirements
D.
Differences in work culture
Answers
D.
Differences in work culture
Suggested answer: C

Explanation:

Conflicting legal requirements would be of greatest concern when consolidating the information security policies of regional locations, as they may pose significant challenges and risks for the organization's compliance, privacy, and data protection obligations. Different jurisdictions may have different laws and regulations regarding information security, such as the General Data Protection Regulation (GDPR) in the European Union, the Health Insurance Portability and Accountability Act (HIPAA) in the United States, or the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada. These laws and regulations may have different definitions, scopes, standards, and enforcement mechanisms for information security, which may create conflicts or inconsistencies when applying a unified policy across the organization. Therefore, the information security manager should conduct a thorough analysis of the legal requirements of each location, and ensure that the consolidated policy meets the highest level of compliance and avoids any violations or penalties.

Reference= CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.22;CISM 2020: IT Security Policies;Information Security Due Diligence Questionnaire

asked 01/10/2024
Kenny McCue
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first