exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 227 discussion

Actual exam question from Isaca's CISM
Question #: 227
Topic #: 1
[All CISM Questions]

An information security manager has identified the organization is not in compliance with new legislation that will soon be in effect. Which of the following is MOST important to consider when determining additional controls to be implemented?

  • A. The information security strategy
  • B. The organization's risk appetite
  • C. The cost of noncompliance
  • D. The information security policy
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sham222
Highly Voted 1 year, 1 month ago
Selected Answer: C
C. Why? Because the risk appetite (B) tells you how much food you can stuff in your mouth at any given time...yet the COST of NC (C) tells you how big the meal is. If you don't know how big the meal is, you won't be able to know if you can tolerate it.
upvoted 10 times
AlexJacobson
7 months, 1 week ago
nice analogy! :)
upvoted 1 times
...
xcjxcj
6 months ago
C neglected cost of compliance (controls) B is closer to gap analysis, which is a better answer
upvoted 1 times
...
...
0884a0d
Most Recent 1 month ago
Selected Answer: B
The key word in the question is legislation. Legislation is a broad law that sets a framework whereas regulations are detailed laws that explain how you must comply with the regulations. Therefore, the question is not asking about the cost of noncompliance. Easy to get caught up in the thought of implementation of new controls and cost if you didn't notice the keyword (legislation vs regulation).
upvoted 1 times
...
shootnot
3 months, 4 weeks ago
C- The question is asking what to consider when determining additional controls to be 'Implemented'. At the implementation stage, u decide whether it's worth it or not. If the question was about 'staying compliant' or not then 'B' would have been appropriate.
upvoted 3 times
...
nuel_12
4 months, 3 weeks ago
Selected Answer: B
the organization risk appetite
upvoted 1 times
...
Thavee
4 months, 4 weeks ago
Selected Answer: B
Appetite first then cost
upvoted 1 times
...
yottabyte
5 months, 2 weeks ago
Selected Answer: B
B seems to be apt for this question
upvoted 1 times
...
oluchecpoint
7 months ago
Selected Answer: B
B. The organization's risk appetite
upvoted 1 times
...
SHERLOCKAWS
8 months, 1 week ago
Selected Answer: C
Considering the cost of noncompliance seems the MOST important to consider when determining additional controls to address the noncompliance. For example, the cost of noncompliance could be high due to industry compliance regulations EVEN IF the organization has high levels of risk acceptance. This is how I see this I hope it helps the community.
upvoted 2 times
...
jcisco123
8 months, 1 week ago
Selected Answer: B
If the cost of noncompliance is high and exceeds the organisation's risk tolerance then addressing noncompliance is essential so knowing risk appetite is the most important to consider.
upvoted 1 times
...
CISSPST
11 months, 1 week ago
Selected Answer: B
Cost of control will also be measured against risk appetite before determining additional controls to be implemented.
upvoted 2 times
CISSPST
11 months, 1 week ago
cost of compliance*
upvoted 1 times
...
...
oluchecpoint
12 months ago
B. The organization's risk appetite While all the options mentioned are important considerations, the organization's risk appetite is crucial because it helps to strike a balance between compliance and the overall risk tolerance of the organization. The level of risk the organization is willing to accept should guide decisions about which controls to implement. Compliance is important, but it should align with the organization's risk management strategy. Implementing controls that are overly costly or restrictive without considering the organization's risk tolerance can lead to inefficiencies or disruptions that may not be acceptable to the organization
upvoted 1 times
...
Goseu
1 year, 1 month ago
Selected Answer: C
I like C here.
upvoted 2 times
...
[Removed]
1 year, 1 month ago
C. Cost of non-compliance first, then you implement that into the risk appetite
upvoted 2 times
...
Rowlandmarc
1 year, 2 months ago
Selected Answer: B
option b
upvoted 1 times
...
richck102
1 year, 2 months ago
B. The organization's risk appetite
upvoted 2 times
...
Saisharan
1 year, 3 months ago
Option B
upvoted 2 times
...
Abhey
1 year, 4 months ago
Selected Answer: B
When determining additional controls to be implemented due to noncompliance with new legislation, the most important consideration is the organization's risk appetite. The risk appetite defines the level of risk that the organization is willing to accept in pursuit of its business objectives, and this will guide the decision-making process regarding which controls to implement. The information security strategy, information security policy, and cost of noncompliance are also important considerations, but they should be evaluated in the context of the organization's risk appetite.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago