ExamGecko
Question list
Search
Search

Question 522 - CISM discussion

Report
Export

A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?

A.
Automated controls
Answers
A.
Automated controls
B.
Security policies
Answers
B.
Security policies
C.
Guidelines
Answers
C.
Guidelines
D.
Standards
Answers
D.
Standards
Suggested answer: D

Explanation:

Standards are the most important thing to review, as they define the specific and mandatory requirements for setting up new user accounts, such as the naming conventions, access rights, password policies, and expiration dates. Standards help to ensure consistency, security, and compliance across the organization's information systems and users. If the standards are not followed, the organization may face increased risks of unauthorized access, data breaches, or audit failures.

Reference= CISM Review Manual 2022, page 341; CISM Exam Content Outline, Domain 1, Knowledge Statement 1.32;CISM 2020: IT Security Policies;Information Security Policy, Standards, and Guidelines

asked 01/10/2024
Raja Tarazi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first