ExamGecko
Question list
Search
Search

Question 674 - CISM discussion

Report
Export

Which of the following should be done NEXT following senior management's decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?

A.
Encrypt data in transit and at rest.
Answers
A.
Encrypt data in transit and at rest.
B.
Complete a return on investment (ROI) analysis.
Answers
B.
Complete a return on investment (ROI) analysis.
C.
Create and implement a data minimization plan.
Answers
C.
Create and implement a data minimization plan.
D.
Conduct a gap analysis.
Answers
D.
Conduct a gap analysis.
Suggested answer: D

Explanation:

A gap analysis is a tool that helps to identify the current state of compliance and the desired state of compliance, as well as the actions needed to achieve the desired state. A gap analysis should be done before implementing any specific controls or solutions, such as encryption, data minimization, or ROI analysis.

Reference=CISM Review Manual 15th Edition, page 65;Information Security Architecture: Gap Assessment and Prioritization, ISACA Journal, volume 2, 2018.

asked 01/10/2024
Landry Tankam
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first