Which of the following is MOST important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy?
The most important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy is the impact on the risk profile. This includes the potential risks that may arise from granting the exception, and any potential impact on the confidentiality, integrity, and availability of the organization's data and systems. This information should be communicated in a clear and concise manner, so that stakeholders can understand the implications of the exception and make an informed decision.
I felt it is C, they are taking exceptions, which means they are going to accept the risks. What needs to be decided next is how often to review these exceptions.
Impact to risk profile and potential compesating controls are already communicated before exception approved. Review period is remaining and best option
Per Review Manual: "Any such policy exceptions must be assessed for risk and impact prior to implementation and the identified risk accepted by appropriate levels of management."
B. Need for compensating controls.
Communicating the need for compensating controls ensures that stakeholders understand how the increased risk associated with the exception will be mitigated and helps maintain a reasonable level of security while accommodating specific business needs.
Communicating the impact on the risk profile is crucial because exceptions to the information security policy have the potential to introduce additional risks to the organization. By clearly articulating the impact, the information security manager can help stakeholders understand the potential consequences and make informed decisions regarding the exception.
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Broesweelies
Highly Voted 1 year, 9 months ago03allen
Most Recent 5 months, 2 weeks agoe891cd1
6 months, 3 weeks agoManix
11 months, 3 weeks agoImTired
1 year agooluchecpoint
1 year, 1 month agowello
1 year, 4 months agorichck102
1 year, 4 months agoDravidian
1 year, 6 months agoDelTrotter
1 year, 10 months ago