exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 109 discussion

Actual exam question from Isaca's CISM
Question #: 109
Topic #: 1
[All CISM Questions]

A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?

  • A. Security policies
  • B. Automated controls
  • C. Guidelines
  • D. Standards
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 4 months ago
Selected Answer: D
The correct answer is D: Standards The reason for this as followed: (a) Security policies - dictate what must be done, but not how. This leaves it open to interpretation and thus the possibilities for inconsistencies. (b) Automated Control do make things consistent, but this is not the security manager's role. This is a tech solution. (c) Guidelines are suggestions, not mandatory things to do, and thus can result in inconsistencies. (d) Standard make things mandatory and consistent. Thus why it's the correct answer.
upvoted 9 times
...
Maccaoidh
Highly Voted 1 year, 4 months ago
Selected Answer: D
Policies should not include procedures (that question comes up routinely). Uniformity of creating user accounts would be listed under a procedure.
upvoted 5 times
...
Noragretz
Most Recent 1 month, 1 week ago
Selected Answer: A
I believe it’s policy. In the policy it should state that standards should be developed to achieve consistency in configurations. If that is not in the policy, then the standard may not even exist.
upvoted 1 times
...
xcjxcj
6 months ago
Selected Answer: D
This is one of the main differences between a policy and standard: Policies act as a statement of intent, while standards function as rules to achieve that intent.
upvoted 1 times
...
oluchecpoint
12 months ago
D. standards provide the specific instructions needed to ensure that user account setups are performed uniformly, making them the most important aspect to review in this situation. Once standards are established and enforced, policies, automated controls, and guidelines can complement them in maintaining a robust security posture.
upvoted 1 times
...
jennarink13
1 year, 1 month ago
I believe A. The policies should provide the proper guidance as whether the nonuniformity is acceptable or not. Any exceptions to the policies should have undergo a proper exception process. This is also true when we do our audits. We normally trace any deficiencies we note in our testing back to the audit client's policies to validate.
upvoted 1 times
jennarink13
1 year, 1 month ago
sorry for any typos tho. wrote in a rush
upvoted 1 times
...
...
Jae_kes
1 year, 2 months ago
Selected Answer: A
A. Security policies When a recent audit reveals that new user accounts are not set up uniformly, the most important area for the information security manager to review is the organization's security policies. Security policies provide the overarching guidelines and directives for establishing and managing user accounts in a consistent and secure manner.
upvoted 2 times
[Removed]
1 year, 2 months ago
stop using chatgpt, it doesnt give correct answers
upvoted 1 times
...
...
richck102
1 year, 3 months ago
D. Standards
upvoted 3 times
...
mad68
1 year, 3 months ago
Selected Answer: D
Standards give details on how to achieve policy compliance
upvoted 2 times
...
Abhey
1 year, 3 months ago
Selected Answer: A
The most important thing for the information security manager to review in this case is the security policies.
upvoted 1 times
...
Seasondream
1 year, 4 months ago
Selected Answer: D
Standards are specific technical applications of something to be implemented. For example you will make accounts utilizing XYZ. Policies are vague and do not have technical jargon. For example "Sensitive data must be protected" is something in a policy. If you changed it to say "Sensitive data will be protected using high end encryption and MFA" that's a standard
upvoted 3 times
...
bambs
1 year, 5 months ago
Selected Answer: A
Security policies are the MOST important for the information security manager to review when a recent audit found that an organization's new user accounts are not set up uniformly.
upvoted 1 times
...
CarlPTY07
1 year, 5 months ago
Selected Answer: D
This is about proper configurations. So its D. Standards: An organization’s security standards describe, in detail, the methods, techniques, technologies, specifications, brands, and configurations to be used throughout the organization. Gregory, Peter H.; Gregory, Peter H.. CISM Certified Information Security Manager Bundle (p. 115). McGraw Hill LLC. Kindle Edition.
upvoted 2 times
...
[Removed]
1 year, 5 months ago
Standards are specific and measurable guidelines that establish a common framework for implementing security controls. They provide a set of rules that all users must follow when creating new user accounts, ensuring uniformity and consistency across the organization. Standards also help to ensure compliance with legal and regulatory requirements, as well as industry best practices
upvoted 2 times
...
Rowlandmarc
1 year, 6 months ago
Selected Answer: A
logic for A is top down approach on documentation..... Logic for D is bottom up on documentation... Documentation should follow the waterfall down so I can't understand why standards (D) are the answer
upvoted 1 times
...
vavofa5697
1 year, 6 months ago
Selected Answer: A
I think it should be A. Security Policies. Security policies define the security requirements and standards for the organization, and ensure that all employees are following the same procedures for new user accounts
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago