exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 224 discussion

Actual exam question from Isaca's CISM
Question #: 224
Topic #: 1
[All CISM Questions]

Which of the following is MOST important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy?

  • A. Impact on the risk profile
  • B. Need for compensating controls
  • C. Time period for review
  • D. Requirements for senior management reporting
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: A
The most important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy is the impact on the risk profile. This includes the potential risks that may arise from granting the exception, and any potential impact on the confidentiality, integrity, and availability of the organization's data and systems. This information should be communicated in a clear and concise manner, so that stakeholders can understand the implications of the exception and make an informed decision.
upvoted 7 times
...
03allen
Most Recent 5 months, 2 weeks ago
Selected Answer: C
I felt it is C, they are taking exceptions, which means they are going to accept the risks. What needs to be decided next is how often to review these exceptions.
upvoted 1 times
...
e891cd1
6 months, 3 weeks ago
B..If it's an exception that stakeholders should know the compensation controls so they could know the mitigation process for these risk .
upvoted 1 times
...
Manix
11 months, 3 weeks ago
Selected Answer: C
Impact to risk profile and potential compesating controls are already communicated before exception approved. Review period is remaining and best option
upvoted 3 times
...
ImTired
1 year ago
Selected Answer: A
Per Review Manual: "Any such policy exceptions must be assessed for risk and impact prior to implementation and the identified risk accepted by appropriate levels of management."
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
B. Need for compensating controls. Communicating the need for compensating controls ensures that stakeholders understand how the increased risk associated with the exception will be mitigated and helps maintain a reasonable level of security while accommodating specific business needs.
upvoted 3 times
...
wello
1 year, 4 months ago
Selected Answer: A
Communicating the impact on the risk profile is crucial because exceptions to the information security policy have the potential to introduce additional risks to the organization. By clearly articulating the impact, the information security manager can help stakeholders understand the potential consequences and make informed decisions regarding the exception.
upvoted 1 times
...
richck102
1 year, 4 months ago
B. Need for compensating controls
upvoted 1 times
...
Dravidian
1 year, 6 months ago
Selected Answer: B
I would think that if they're at the point of approving then they have already past talking about impacts.
upvoted 2 times
...
DelTrotter
1 year, 10 months ago
Selected Answer: A
Risk profile.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago