exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 528 discussion

Actual exam question from Isaca's CISM
Question #: 528
Topic #: 1
[All CISM Questions]

When developing security processes for handling credit card data on the business unit's information system, the information security manager should FIRST:

  • A. ensure that systems that handle credit card data are segmented.
  • B. review industry best practices for handling secure payments.
  • C. ensure alignment with industry encryption standards.
  • D. review corporate policies regarding credit card information.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bdabef2
1 week, 4 days ago
Selected Answer: D
Answer is D, the policy will provide the guidance that's needs to be followed which should include adherence to standards such as PCI DSS.
upvoted 1 times
...
AlexJacobson
8 months, 2 weeks ago
Selected Answer: D
D is basically a gap analysis, so I feel it's the most correct place to start.
upvoted 1 times
xcjxcj
7 months, 2 weeks ago
(PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment. Unlike other security standards, you can have your own company policy (lower than industry standard) as baseline, PCI-DSS is the baseline B. is preferred
upvoted 2 times
...
...
koala_lay
1 year ago
Selected Answer: D
The information security manager FIRST review corporate policies regarding credit card information. This step is crucial as it sets the foundation for security processes within the organization. By understanding and adhering to the corporate policies, the information security manager can ensure that the handling of credit card data aligns with the organization's guidelines and compliance requirements. This step provides a framework for implementing appropriate security measures and helps address any potential gaps or issues in the existing policies. Once this foundation is established, the information security manager can then proceed to the other options mentioned, such as ensuring systems are segmented, reviewing industry best practices, and ensuring alignment with encryption standards.
upvoted 4 times
...
Cert_IT
1 year, 1 month ago
Selected Answer: B
B. Review industry best practices for handling secure payments.
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: D
D. Review corporate policies regarding credit card information. This is the first step because it's essential to understand the organization's existing policies and compliance requirements related to credit card data handling. Once you have a clear understanding of the internal policies, you can then proceed to align with industry encryption standards (option C), review industry best practices (option B), and ensure that systems are segmented (option A). However, the foundation for secure credit card data handling is established by adhering to your organization's policies and compliance mandate
upvoted 1 times
...
Bl1024
1 year, 1 month ago
Selected Answer: A
Why not A? CC Data must be segmented as a first measure of protection Policies and standards come on top of that
upvoted 1 times
...
devilend
1 year, 3 months ago
Selected Answer: B
upvoted 1 times
...
richck102
1 year, 3 months ago
D. review corporate policies regarding credit card information.
upvoted 2 times
...
shiowbah
1 year, 7 months ago
B. review industry best practices for handling secure payments.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago