ExamGecko
Question list
Search
Search

Question 569 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST when there is a conflict between the organization's information security policy and a local regulation?

A.
Enforce the local regulation.
Answers
A.
Enforce the local regulation.
B.
Obtain legal guidance.
Answers
B.
Obtain legal guidance.
C.
Enforce the organization's information security policy.
Answers
C.
Enforce the organization's information security policy.
D.
Obtain an independent assessment of the regulation.
Answers
D.
Obtain an independent assessment of the regulation.
Suggested answer: B

Explanation:

The information security manager should first obtain legal guidance when there is a conflict between the organization's information security policy and a local regulation, because this will help to understand the implications and consequences of the conflict, and to identify the possible options and solutions for resolving it. The information security manager should also consult with the relevant stakeholders, such as senior management, business owners, and information owners, to determine the best course of action that aligns with the organization's objectives, risk appetite, and compliance obligations. Enforcing the local regulation or the organization's information security policy without legal guidance may expose the organization to legal liabilities, security risks, or operational disruptions. Obtaining an independent assessment of the regulation may be helpful, but it is not the first step to take.

Reference= CISM Review Manual, 16th Edition, page 691; A Guide to ISACA CISM Domains & Domain 1: Information Security Governance2

asked 01/10/2024
Markus Hechtl
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first