ExamGecko
Question list
Search
Search

Question 606 - CISM discussion

Report
Export

An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?

A.
Control owner responses based on a root cause analysis
Answers
A.
Control owner responses based on a root cause analysis
B.
The impact of noncompliance on the organization's risk profile
Answers
B.
The impact of noncompliance on the organization's risk profile
C.
A noncompliance report to initiate remediation activities
Answers
C.
A noncompliance report to initiate remediation activities
D.
A business case for transferring the risk
Answers
D.
A business case for transferring the risk
Suggested answer: B

Explanation:

The impact of noncompliance on the organization's risk profile is the MOST important information for the information security manager to communicate to senior management, because it helps them understand the potential consequences of not adhering to the established controls and the need for corrective actions. Noncompliance may expose the organization to increased threats, vulnerabilities, and losses, as well as legal, regulatory, and contractual liabilities.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 84: ''The information security manager should report on information security risk, including noncompliance and changes in information risk, to key stakeholders to facilitate the risk management decision-making process.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 85: ''Noncompliance with information security policies, standards, and procedures may result in increased threats, vulnerabilities, and losses, as well as legal, regulatory, and contractual liabilities for the enterprise.''

asked 01/10/2024
Wilson Sigcha
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first