ExamGecko
Question list
Search
Search

Question 557 - CISM discussion

Report
Export

Internal audit has reported a number of information security issues that are not in compliance with regulatory requirements. What should the information security manager do FIRST?

A.
Create a security exception.
Answers
A.
Create a security exception.
B.
Perform a gap analysis to determine needed resources.
Answers
B.
Perform a gap analysis to determine needed resources.
C.
Perform a vulnerability assessment.
Answers
C.
Perform a vulnerability assessment.
D.
Assess the risk to business operations.
Answers
D.
Assess the risk to business operations.
Suggested answer: D

Explanation:

The information security manager should first assess the risk to business operations that are caused by the information security issues reported by internal audit. This will help to prioritize the remediation actions and allocate the necessary resources. Creating a security exception, performing a gap analysis, or performing a vulnerability assessment are possible subsequent steps, but they are not the first action to take.

Reference= CISM Review Manual, 16th Edition, page 48

asked 01/10/2024
matias alvarez
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first