Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 420 discussion

Actual exam question from Isaca's CISM
Question #: 420
Topic #: 1
[All CISM Questions]

Which of the following roles is accountable for ensuring the impact of a new regulatory framework on a business system is assessed?

  • A. Senior management
  • B. Application owner
  • C. Legal representative
  • D. Information security manager
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: A
Senior management is typically accountable for ensuring that the impact of a new regulatory framework on a business system is assessed. They are responsible for overseeing the overall operations of the organization and making strategic decisions that align with the organization's goals and objectives. As such, they are in a position to ensure that the necessary resources and support are allocated to assess the impact of new regulations on the organization's systems and to develop and implement the appropriate compliance measures. Additionally, senior management is responsible for ensuring that the organization is in compliance with all relevant laws and regulations, and therefore should be aware of any new regulations that may affect the business.
upvoted 10 times
...
Agamennore
Highly Voted 1 year, 2 months ago
Selected Answer: A
A. Senior management = accountable B. Application owner = responsible C. Legal representative = consulted D. Information security manager = informed
upvoted 7 times
...
e891cd1
Most Recent 4 months, 3 weeks ago
B. Following the RACI framework..Responsible Accountable Consult Inform.. The application would be accountable
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: D
D - Information security Manager
upvoted 1 times
...
jcisco123
10 months, 3 weeks ago
Selected Answer: D
"The information security manager is responsible for ensuring that the impact of changes in the external environment, such as new regulations, is assessed for their impact on the organization's information security."
upvoted 2 times
...
POWNED
11 months, 3 weeks ago
Selected Answer: D
Anyone who did not answer D needs to give up on taking this test.
upvoted 2 times
AlexJacobson
9 months, 3 weeks ago
Wow...the level of confidence in you, yet you're forgetting about the basic thing such as RACI.
upvoted 3 times
Raven89
2 weeks, 6 days ago
yes, he is so confident but he does not know the difference between responsable and accountable
upvoted 1 times
...
...
...
Soleandheel
12 months ago
D. Information security manager. Senior management is ultimately responsible to ensure that the organization is compliant with laws and regulations. However, when it comes to ensuring that the impact of a new regulatory framework on a business system is assessed, that is the responsibility of the Information Security Manager. Senior management will hold the information security Manager accountable for it.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: D
The CISM (Certified Information Security Manager) Review Manual, 27th Edition, emphasizes this by stating: "The information security manager is responsible for ensuring that the impact of changes in the external environment, such as new regulations, is assessed for their impact on the organization's information security."
upvoted 1 times
JanBas
7 months, 2 weeks ago
your quote above says 'impact on the organization's information security', but the questions ask for impact on the business application. i believe it should be the app owner who should be responsible for assessing it. so B is the correct answer
upvoted 1 times
...
AlexJacobson
9 months, 3 weeks ago
Accountable =/= Responsible
upvoted 1 times
...
...
Saisharan
1 year, 4 months ago
based on the keyword "accountable," the answer would be A. Senior management.
upvoted 1 times
...
richck102
1 year, 4 months ago
A. Senior management = accountable B. Application owner = responsible C. Legal representative = consulted D. Information security manager = informed
upvoted 1 times
richck102
1 year, 4 months ago
B. Application owner
upvoted 1 times
...
...
karanvp
1 year, 4 months ago
I think the keyword here is "ensuring the impact". I think business owner only can ensure the impact, not Sr. Management
upvoted 2 times
...
Saisharan
1 year, 5 months ago
Information Security Manager (option D). The Information Security Manager is responsible for overseeing and managing the organization's information security program. This includes assessing the impact of new regulations or regulatory frameworks on the organization's systems and processes. They work closely with various stakeholders, including senior management, legal representatives, and application owners, to ensure compliance with applicable regulations.
upvoted 2 times
...
mad68
1 year, 6 months ago
Selected Answer: A
If the key word in the question is "accountable," then the correct answer would be A. Senior management. Senior management is ultimately accountable for ensuring that the impact of a new regulatory framework on a business system is assessed. While the information security manager may be responsible for conducting the assessment and providing recommendations, senior management has the overall accountability for ensuring that the assessment is carried out and appropriate actions are taken.
upvoted 1 times
...
Dravidian
1 year, 6 months ago
Selected Answer: B
It's new regulation on a business system. Senior management cannot be aware of every new regulation that comes out there. It is the responsibility of the Business Owner aka Application Owner to stay on top of regulations that fall in their domain.
upvoted 6 times
...
dark_3k03r
1 year, 7 months ago
Selected Answer: A
The way to think about this question is in form of a RACI. When you think about it this way, the correct answer is (A) Senior Management as they are most likely to be the ones that own the system. Rationale: (B.) Application owner(s) are only accountable for what occurs in the apps, but not the system. C. Legal representatives are consulted on legal manners, but the accountability can not be outsourced to them... it stays with the owner. (D) Information security manager may be consulted on technical manners, but the accountability can not be outsourced to them... it stays with the owner.
upvoted 1 times
...
aokisan
1 year, 11 months ago
Selected Answer: D
clearly, D. not application owner.
upvoted 5 times
prpslux
1 year, 10 months ago
The owner is the person that has the proper knowledge to properly evaluate the impact.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...