Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 735 discussion

Actual exam question from Isaca's CISM
Question #: 735
Topic #: 1
[All CISM Questions]

An information security manager is concerned with continued security policy violations in a particular business unit despite recent efforts to rectify the situation. What is the BEST course of action?

  • A. Review the business unit’s function against the policy
  • B. Revise the policy to accommodate the business unit
  • C. Report the business unit for policy noncompliance
  • D. Enforce sanctions on the business unit
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
N1co_o
Highly Voted 1 year, 8 months ago
Selected Answer: C
"despite recent efforts to rectify the situation". Going for C
upvoted 11 times
AlexJacobson
9 months, 3 weeks ago
But how we know that "despite recent efforts to rectify the situation" actually mean that infosec manager has already reviewed the policy and checked it against business unit function? It could easily mean that he/she just told them "hey guys, you're violating the policy, you have to do it like this" but they just couldn't since policy isn't aligned/written good enough. Escalation is a drastic course of action and should be avoided whenever possible.
upvoted 2 times
...
karanvp
1 year, 4 months ago
Yes, this statement leading to option C.
upvoted 1 times
...
...
Booict
Most Recent 3 months ago
Selected Answer: A
A - helps identify the root cause of the continued policy violations. Option C is not going to address the non-compliance issue.
upvoted 1 times
...
03allen
4 months, 3 weeks ago
Selected Answer: A
there is no controversy between A and the 'recent rectify efforts'
upvoted 1 times
...
Thavee
7 months ago
Selected Answer: A
All employees' norms are not to violate company's policies, but if that ever happened, there must be some reasons behind. "recent efforts to rectify the situation" did not tell much about the severity of the situation. the sentence is kind of exaggerating. For the sake of peaceful world, before starting the war, ISM should review first.
upvoted 1 times
...
Salilgen
8 months, 1 week ago
Selected Answer: C
"recent efforts to rectify the situation" suggests that A has already been done. If so, answer is C
upvoted 1 times
...
Uncle_Lucifer
11 months, 2 weeks ago
Selected Answer: C
"despite recent efforts to rectify the situation" --> C A is invalid because he/she (SM) already did it
upvoted 2 times
...
AaronS1990
1 year, 2 months ago
Selected Answer: C
C is correct. “Continued violations despite efforts to rectify”. That to me is time to escalate the issue. There’s only so long you can have people going against the policy put in place to protect the business before things need to be escalated both for your sake, and the business’.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: A
A. Review the business unit's function against the policy: It's essential to first understand why the policy violations are occurring. Conduct a thorough review of the business unit's operations, processes, and specific challenges that may be causing the violations. Identify any gaps or conflicts between the policy and the business unit's needs or objectives.
upvoted 1 times
...
paul1394
1 year, 3 months ago
Selected Answer: A
The best course of action for the information security manager to address continued security policy violations in a business unit is to review the unit's business function against the policy requirements. There may be a valid gap between the policy and actual business needs that requires reconciliation. The goal should be to understand the root causes driving the violations. Revising the policy immediately to accommodate the unit undermines policy integrity and consistency. Reporting noncompliance and enforcing sanctions will not address the underlying issue. Reviewing the specific business processes and use cases against the policy provides insights on whether the violations stem from outdated policy requirements that need updating, lack of security control effectiveness, or a business need for risk acceptance. This enables the most appropriate rectification.
upvoted 2 times
...
richck102
1 year, 4 months ago
A. Review the business unit’s function against the policy
upvoted 1 times
...
Dopy
1 year, 5 months ago
Selected Answer: A
to escalate will only cause issues in the organisation and make security a target, by reviewing the business unit's function against the security policy you are working with them not against them and so a better chance of success
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: A
A. Review the business unit's function against the policy. By reviewing the business unit's function against the security policy, the information security manager can assess whether the policy is aligned with the specific needs and requirements of the business unit. This review helps identify any potential gaps or conflicts between the policy and the operational realities of the unit. It allows for a better understanding of why the policy violations are occurring and provides an opportunity to address any underlying issues.
upvoted 3 times
...
mad68
1 year, 6 months ago
Selected Answer: A
A. Review the business unit's function against the policy. By reviewing the business unit's function against the security policy, the information security manager can assess whether the policy is aligned with the specific needs and requirements of the business unit. This review helps identify any potential gaps or conflicts between the policy and the operational realities of the unit. It allows for a better understanding of why the policy violations are occurring and provides an opportunity to address any underlying issues.
upvoted 2 times
...
bambs
1 year, 8 months ago
Selected Answer: A
The BEST course of action for an information security manager concerned with continued security policy violations in a particular business unit despite recent efforts to rectify the situation is to review the business unit’s function against the policy.
upvoted 4 times
...
CarlPTY07
1 year, 8 months ago
Selected Answer: C
C is the right one. We already try to do all we can do..,now it time for escalation.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...