Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 920 discussion

Actual exam question from Isaca's CISM
Question #: 920
Topic #: 1
[All CISM Questions]

Which of the following should be performed FIRST in response to a new information security regulation?

  • A. Industry benchmarking
  • B. Independent audit
  • C. Risk assessment
  • D. Gap analysis
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Raj91188
1 month, 4 weeks ago
C. Risk assessment. Agree with Booict comment.
upvoted 1 times
...
Booict
3 months, 3 weeks ago
My answer is C. The key word is "new regulation". The option D (Gap analysis) is chosen only is there is amendment or update to the existing regulation.
upvoted 1 times
...
POWNED
9 months, 3 weeks ago
Go look at the NIST 500 series for RMF. Yes its a massive series of checklists for compliance. Now imagine this new regulation is similar (probably not as big). You need to go through the checklist and identify where you ISP fails in coverage (This would be the gap analysis). Once you have identified the gaps you will then move into risk assessment.
upvoted 3 times
...
POWNED
9 months, 3 weeks ago
Selected Answer: D
Correct answer is D, check explanation under reply to AlexJacobson
upvoted 3 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: C
It's C. Assess the risk of non-compliance first, then if the risk is outside of acceptable parameters you go ahead and start preparations to implement the new regulation by figuring out your current state of affairs against the new regulation (i.e. doing gap analysis).
upvoted 1 times
POWNED
9 months, 3 weeks ago
I understand your confusion, but if you made it this far in the test questions you should know by now that the answer is D. You need to do a gap analysis first in order to see if the risk is already covered, or identify in what places it is not. You will then go through with a risk assessment to verify it is within scope of risk acceptance.
upvoted 1 times
AlexJacobson
9 months, 2 weeks ago
While I don't necessary disagree with you, I urge you to be careful with assuming correct answers based on previous questions. I actually analyzed this and other question banks and concluded that while questions do repeat somewhat, they usually come with slightly different answers, or the question is worded just a bit differently, but enough to make a different answer the correct one. Just like people assuming that whenever they see "senior management buy-in" or "senior management support" they automatically choose that answer because they think that's the one that is always correct (which is not).
upvoted 1 times
...
...
...
TamerBeSafe
9 months, 4 weeks ago
Selected Answer: D
The correct answer is D. Gap analysis. the Step of GAP assessment is before the Risk Assessment
upvoted 2 times
AlexJacobson
9 months, 3 weeks ago
I still don't understand why would gap analysis be the first step... I mean, first you need to assess the risks of non-compliance and only if it is concluded that it's outside of risk appetite/tolerance/capacity you start preparing to implement the regulatory requirement by doing gap analysis.
upvoted 1 times
...
...
Soleandheel
11 months, 3 weeks ago
Stop over-analyzing. The correct answer is D. Gap analysis. You need to analyze the gap between your current state and the desired state (which will be adopting the new regulation).
upvoted 2 times
...
Cyberbug2021
12 months ago
Selected Answer: C
BIA - Risk Assessment - Gap Analysis
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: D
Gap Analysis from the list. First BIA - what is the impact to the business of the new regulations then Gap Analysis - gap between existing and new Risk Asessment
upvoted 1 times
Cyberbug2021
12 months ago
Take that back - Risk Assessment before Gap Analysis
upvoted 2 times
...
...
koala_lay
1 year ago
Selected Answer: C
The first step in response to a new information security regulation should be a risk assessment. This involves identifying and assessing potential risks and vulnerabilities in your current information security practices and systems. By conducting a comprehensive risk assessment, you can gain a clear understanding of the potential impact of the new regulation on your organization and prioritize your efforts accordingly. This will help you identify the areas that need improvement and allocate resources effectively. Once the risk assessment is completed, you can proceed with other measures such as industry benchmarking, independent audit, and gap analysis to ensure compliance with the regulation.
upvoted 3 times
...
richck102
1 year, 1 month ago
Selected Answer: C
i vote C. Risk assessment
upvoted 1 times
...
secdoc
1 year, 1 month ago
Assess if the regulation even applies to the organization and if it does conduct a Gap Analysis, create a business case for closing the gap and present to senior management
upvoted 2 times
...
Saisharan
1 year, 1 month ago
The question is about - in response to a new information security regulation - means after implementing a security regulation - so the answer is risk assessment. Previous questions - the question was asked about before implementing the new information security regulation - then the answer would be Gap analysis.
upvoted 2 times
POWNED
9 months, 3 weeks ago
You are wrong they are both before implementation.
upvoted 1 times
...
...
wickhaarry
1 year, 1 month ago
D. Gap analysis The gap analysis aims to identify areas of improvement or potential risks that may affect operations. Risk assessment aims to identify and prioritize areas of risk so actions can be taken to mitigate them.
upvoted 4 times
...
BennyMao
1 year, 2 months ago
Selected Answer: D
Gap analysis should be done first, then risk assessment.
upvoted 3 times
...
CISSPST
1 year, 2 months ago
Regulations should be treated as any other risk, therefore requiring a risk assessment. Gap analysis is more pertinent to control assessment.
upvoted 1 times
CISSPST
1 year, 2 months ago
Answer is risk assessment.
upvoted 1 times
...
...
CISM2023
1 year, 2 months ago
Why not GAP ANALYSIS? In this same question bank we have seen previously it was GAP ANALYSIS
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...