Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 269 discussion

Actual exam question from Isaca's CISM
Question #: 269
Topic #: 1
[All CISM Questions]

What is the BEST approach for the information security manager to reduce the impact on a security program due to turnover within the security staff?

  • A. Recruit certified staff
  • B. Revise the information security program
  • C. Document security procedures
  • D. Ensure everyone is trained in their roles
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 7 months ago
Selected Answer: C
The correct answer is (C) Document security procedures, cause anyone who has access to the procedures is able to learn from them and reproduce the same results using the same process. A. When the certified user leaves another one may bring a different approach B. Revise the information security program does nothing to address the issue of turnover, only the objectives of the program. D. Ensure everyone is trained in their roles is a great idea, but once they leave and another group enters, the process may be inconsistent and thus doing nothing to minimize the impact.
upvoted 7 times
...
Jess20
Most Recent 3 weeks, 4 days ago
Selected Answer: C
reduce the impact of people leaving? C. Why not D? What is the benefit on training people leaving? You need documentation that helps the new hires on how to do the work
upvoted 1 times
...
oluchecpoint
9 months, 3 weeks ago
Selected Answer: C
C. Document security procedures
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
D. All the options have their merits, ensuring that everyone on the security team is adequately trained in their roles is the most immediate and effective way to address the impact of turnover on a security program.
upvoted 1 times
...
richck102
1 year, 5 months ago
C. Document security procedures
upvoted 1 times
...
Abhey
1 year, 6 months ago
Selected Answer: D
By training the existing and new security staff on their roles and responsibilities, the information security manager can ensure that the security program continues to function effectively. This will also help ensure consistency in security operations and maintain compliance with security policies and regulations. Documenting security procedures and revising the information security program can also help in reducing the impact of staff turnover, but training is the primary solution.
upvoted 2 times
...
dedfef
1 year, 7 months ago
Selected Answer: C
documenting procedures allows for sustainability of processes
upvoted 2 times
...
[Removed]
1 year, 8 months ago
need to ensure consistency with policies therefore documenting would ensure new staff members follow same procedures
upvoted 1 times
...
bambs
1 year, 10 months ago
Selected Answer: D
When you document your procedures without training your stakeholders, that can end in a terrible catastrophe. i choose D
upvoted 1 times
Feard
1 year, 9 months ago
What value do you get when a well trained resource leaves? I believe there is more to gain from the documentation that remains for the newbies to use.
upvoted 5 times
Rowlandmarc
1 year, 8 months ago
agree - the training of the stakeholders should be done through documentation of procedures too
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...