Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 469 discussion

Actual exam question from Isaca's CISM
Question #: 469
Topic #: 1
[All CISM Questions]

Which of the following is the BEST approach to identify new security issues associated with IT systems and applications in a timely manner?

  • A. Requiring periodic security audits of IT systems and applications
  • B. Comparing current state to established industry benchmarks
  • C. Performing a vulnerability assessment for each change to IT systems
  • D. Integrating risk assessments into the change management process
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
AaronS1990
Highly Voted 1 year, 3 months ago
"new security issues associated with IT systems" If it said "security issues with new systems" i'd understand why it's D. But in this case we aren't really talking about making changes to a system, rather keeping an eye out for emerging threats to existing systems. This looks more like A to me... Anyone else have any thoughts?
upvoted 9 times
...
Booict
Most Recent 2 months, 2 weeks ago
Selected Answer: D
D for me. Any potential security issues are identified and addressed as part of the routine process of making changes to IT systems and applications. Option A is important too, but may not be as timely since audits are typically conducted at set intervals and may miss issues that arise between audits.
upvoted 2 times
...
Thavee
7 months, 1 week ago
Selected Answer: D
Best approach to identify "NEW security issues" For example, CVE xxx regarding OS xxx ---> ISM learns new patches needed ---> Assessment --> then D. If A. periodic sec audits --> quarterly, semi annually, or yearly --> not a timely manner
upvoted 1 times
...
shervin2s
8 months ago
Selected Answer: A
Integrating risk assessments into the change management process will not Identify the security issues will prevent them.
upvoted 1 times
...
AlexJacobson
9 months, 4 weeks ago
Selected Answer: A
My thinking is very close to AaronS1990's. Going with A on this one.
upvoted 1 times
...
6and0
1 year, 2 months ago
Selected Answer: A
A. Requiring periodic security audits of IT systems and applications I agree with AaronS1990.. If this is happening periodically then it would have a better chance of identifying a security issue in a "timely manner". D. Integrating risk assessments into the change management process - While its a good thing there's no guarantee that there will be any changes applied thus initiating an assessment.
upvoted 4 times
...
richck102
1 year, 4 months ago
Selected Answer: D
D. Integrating risk assessments into the change management process
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...