ExamGecko
Question list
Search
Search

Question 538 - CISM discussion

Report
Export

An organization recently updated and published its information security policy and standards. What should the information security manager do NEXT?

A.
Conduct a risk assessment.
Answers
A.
Conduct a risk assessment.
B.
Communicate the changes to stakeholders.
Answers
B.
Communicate the changes to stakeholders.
C.
Update the organization's risk register.
Answers
C.
Update the organization's risk register.
D.
Develop a policy exception process.
Answers
D.
Develop a policy exception process.
Suggested answer: B

Explanation:

Communicating the changes to stakeholders is the next step after updating and publishing the information security policy and standards, as it ensures that the stakeholders are aware of the new or revised requirements, expectations and responsibilities, and can provide feedback or raise concerns if needed. Communication also helps to promote the acceptance and adoption of the policy and standards, and to reinforce the security culture and awareness within the organization. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Aleph Ventures
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first