Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 15 discussion

Actual exam question from Isaca's CISM
Question #: 15
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to ensure that organizational security policies comply with data security regulatory requirements?

  • A. Obtain annual sign-off from executive management.
  • B. Align the policies to the most stringent global regulations.
  • C. Send the policies to stakeholders for review.
  • D. Outsource compliance activities.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
niki83
Highly Voted 1 year, 8 months ago
C. Send the policies to stakeholders for review.
upvoted 10 times
...
Viperhunter
Highly Voted 1 month, 3 weeks ago
Selected Answer: B
Aligning security policies with the most stringent global regulations helps ensure that the organization meets high standards for data security and compliance. This approach not only ensures adherence to local regulations but also provides a robust framework that can address various regulatory requirements across different jurisdictions. While obtaining annual sign-off from executive management (option A) and sending policies to stakeholders for review (option C) are valuable practices, aligning with the most stringent global regulations provides a comprehensive and proactive strategy for regulatory compliance. Outsourcing compliance activities (option D) can be a consideration, but it does not replace the need for a well-defined and internally aligned security policy framework.
upvoted 5 times
...
alt_coffey
Most Recent 1 month, 3 weeks ago
Selected Answer: C
C. ISACA thinks of stakeholders as experts in their field and know which policies to follow. The problem with B is that it's "Global", but there could be more stringent local policies that are not addressed globally.
upvoted 2 times
...
Azurefox79
1 month, 3 weeks ago
Selected Answer: B
B is the only relevant answer here. It would ensure that your policies cover EVERY requirement, regardless of jurisdiction. Think of a company that does HITRUST, they woul meet NIST, HIPAA and PCI requirements as well since they are a part of HITRUST. That ensures they follow a single framework but are covering all bases.
upvoted 4 times
...
romero318
1 month, 3 weeks ago
Selected Answer: B
Honestly looking at this question can be tricky. They simply ask what is the best way. They did not ask how to assure standards are met. If you were to instruct a engineer on how to do the job you would tell them to align the policies to the most stringent global regulations. Remember they are simply asking what is the best way.
upvoted 3 times
...
greeklover84
2 months ago
Selected Answer: B
B makes sense.
upvoted 1 times
...
BamBamBigalo
5 months, 1 week ago
B. Align the policies to the most stringent global regulations. Aligning policies to the most stringent global regulations can be a robust approach to ensuring compliance, as it helps to cover a wide range of regulatory requirements. This method ensures that the organization meets or exceeds the highest standards, which can provide a strong foundation for compliance across various jurisdictions
upvoted 1 times
...
vipulsinghal2903
7 months, 1 week ago
Selected Answer: C
It says best. Most stringest is never best (given high cost). As such C.
upvoted 3 times
...
mwalula
8 months ago
To me the answer is C. B is incorrect because the most strict global regulations have a very high chance of conflicting with local regulations.
upvoted 1 times
...
shervin2s
8 months, 2 weeks ago
Selected Answer: B
B is correct
upvoted 2 times
...
Marcelus1714
9 months ago
Selected Answer: B
Align the policies to the most stringent global regulations for sure your policies will be compliant, pretty logic...
upvoted 2 times
...
Lalyaaa
9 months, 1 week ago
Selected Answer: C
C. Send the policies to stakeholders for review.
upvoted 1 times
...
AlexJacobson
10 months ago
Selected Answer: D
I would say it's D for a simple reason that the close second (B) is a waste of resources and is not cost-effective. The BEST and most objective view on the problem can be provided by external auditors. So this should be the best and most cost-effective way to do it.
upvoted 1 times
...
Creations
10 months, 2 weeks ago
I will shoot for B, since regulatory is mentioned
upvoted 1 times
...
acf4e9a
1 year, 1 month ago
Selected Answer: C
Aligning the policies to most stringent global policy would create conflict with local regional policies as each location policies might differ. Other hand business stakeholders are best positioned to take the call if they are impacted or not and choose appropriate risk treatment so engaging business people for review would be most appropriate for this case therefore option C would highly fill the blank here.
upvoted 2 times
...
MrSecNetTech
1 year, 1 month ago
right answer is C. reason that B is wrong: applying the most stringent can not guarantee full compliance to local regulators which differs from a country to other country. Satisfying local regulations has a precedence over satisfying a global. C is right because it gives opportunity to communicate with stakeholders who will be considering the local regulations and has more awareness about it than the global.
upvoted 2 times
...
ItsDougj
1 year, 2 months ago
"Security regulatory requirements" versus "global regulations" is where I am stuck. If I am in banking I care about banking requirements not global. I need to be an sme on banking regulations not global.
upvoted 1 times
aji234
1 year ago
Compliance with the highest standard allows your bank to do business with other businesses anywhere without fear of noncompliance. Remember that we live in a global village. businesses are connected and if not now, as your business grows, you will interface with others so think global
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...