exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 571 discussion

Actual exam question from Isaca's CISM
Question #: 571
Topic #: 1
[All CISM Questions]

A new law requires an organization to implement specific security controls. Which of the following should the information security manager do FIRST?

  • A. Integrate the new requirements into the security policy.
  • B. Perform a gap analysis on the new requirements.
  • C. Develop a control implementation plan.
  • D. Assess the risk of noncompliance with the new requirements.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Josef4CISM
2 days, 23 hours ago
Selected Answer: D
The right answer is D. If the risk of non-compliance is minimal, why doing the bothering task to conduct a gap analysis? It's always: get a clear picture of the situation first and decide for further actions afterwards.
upvoted 1 times
...
ATT5832
1 month, 3 weeks ago
Selected Answer: D
I would assess the risk of non-compliance and put it on the risk register. Then I would proceed with a gap analysis.
upvoted 1 times
d7a2ba6
3 weeks, 5 days ago
But maybe you already comply, or partly comply. So you need to have a GAP analysis first to know that.
upvoted 1 times
...
...
03allen
6 months, 3 weeks ago
Selected Answer: B
Always evaluate how to achieve it first rather than a negative thought about noncompliance.
upvoted 1 times
...
yottabyte
9 months, 3 weeks ago
Selected Answer: B
Perform a gap analysis is the best bet here.
upvoted 2 times
...
AlexJacobson
11 months, 3 weeks ago
Selected Answer: D
As others have said - first D, then other stuff (if necessary; maybe management decides that it's more cost-effective to pay fines then to implement controls).
upvoted 2 times
...
Marcovic00
1 year, 1 month ago
Selected Answer: D
I go with D then B
upvoted 1 times
...
koala_lay
1 year, 3 months ago
Selected Answer: B
Performing a gap analysis involves comparing the organization's current security controls and practices against the specific security controls mandated by the new law. This analysis will identify any gaps or areas where the organization does not meet the requirements.
upvoted 1 times
...
kristofer8
1 year, 3 months ago
Selected Answer: D
D no other option!
upvoted 1 times
...
richck102
1 year, 6 months ago
B. Perform a gap analysis on the new requirements.
upvoted 1 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: B
The first thing the information security manager should do is perform a gap analysis on the new requirements. A gap analysis is a process of comparing the current state of the organization's security against the new legal requirements to identify any areas where the organization falls short of meeting the new requirements. This step is important to identify the specific areas where the organization needs to improve its security controls in order to comply with the new law. Once the gap analysis is complete, the organization can develop a control implementation plan, integrate the new requirements into the security policy, and assess the risk of noncompliance with the new requirements.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago