exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 655 discussion

Actual exam question from Isaca's CISM
Question #: 655
Topic #: 1
[All CISM Questions]

Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?

  • A. Recommend risk acceptance.
  • B. Perform a cost-benefit analysis.
  • C. Escalate to senior management.
  • D. Revisit the business objective.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aokisan
Highly Voted 2 years ago
Selected Answer: B
at first, perform ROI.
upvoted 6 times
...
03allen
Most Recent 6 months, 2 weeks ago
Selected Answer: C
C first
upvoted 2 times
...
Marcelus1714
9 months, 1 week ago
Selected Answer: C
Escalate to senior management.
upvoted 2 times
...
maisarajarrah
1 year ago
Selected Answer: C
C. Escalate to senior management.
upvoted 2 times
...
CISSPST
1 year ago
Selected Answer: B
Before approaching the SM, the infosec manager should do his homework (cost of non-compliance vs benefits of compliance)
upvoted 4 times
realmjmj
1 week, 6 days ago
both consequences are clear here. - "identified" business objects achieved or not.
upvoted 1 times
...
...
Uncle_Lucifer
1 year ago
Selected Answer: C
Escalate based on the scenario - mandatory control, and the bottle kneck to objectives. You would have done the cost benefit-analysis prior to selecting the mandatory requirements. C
upvoted 3 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: C
C. Escalate to senior management. Escalating the issue to senior management allows for a higher-level decision-making process. Senior management can evaluate the situation, consider the potential risks, and make an informed decision regarding whether to adjust the business objective, allocate additional resources, seek exceptions or waivers from the security standard, or take other appropriate actions. After senior management is aware of the issue and involved in the decision-making process, they may then decide to perform a cost-benefit analysis, revisit the business objective, or recommend risk acceptance if necessary.
upvoted 3 times
...
AaronS1990
1 year, 3 months ago
Why would he bother with B when the hindrance is being caused by a mandated control? The question implies that the control must remain in place so how or why would you need to weigh it up?
upvoted 1 times
...
richck102
1 year, 6 months ago
B. Perform a cost-benefit analysis.
upvoted 1 times
...
wello
1 year, 6 months ago
Selected Answer: C
C. Escalate to senior management.
upvoted 2 times
...
Souvik124
1 year, 10 months ago
When a mandatory security standard hinders the achievement of an identified business objective, the information security manager should first perform a cost-benefit analysis to determine the impact of the security standard on the business objective.
upvoted 2 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: B
Very much B in this case
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago