Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 776 discussion

Actual exam question from Isaca's CISM
Question #: 776
Topic #: 1
[All CISM Questions]

In violation of a policy prohibiting the use of cameras at the office, employees have been issued smartphones and tablet computers with enabled web cameras. Which of the following should be the information security manager's FIRST course of action?

  • A. Revise the policy.
  • B. Conduct a risk assessment.
  • C. Communicate the acceptable use policy.
  • D. Perform a root cause analysis.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 7 months ago
Selected Answer: C
The answer should be C. Communicate the acceptable use policy as that is the only one that addresses the issue now. Rationale: A. Revise the policy - This will take time and not do anything for the status quo. B. Conduct a risk assessment - This should be done after the policy has been communicated cause the risk has already occurred. They have phones. The question now is how bad is it going to be. If it's going to be bad as a stop-gap people need to be reminded of the acceptable use policy. D. Perform a root cause analysis - For what? We already know the cost.
upvoted 7 times
...
Souvik124
Highly Voted 1 year, 9 months ago
The information security manager's FIRST course of action should be to communicate the acceptable use policy. Therefore, the correct answer is option C.
upvoted 5 times
cosmo4ng
1 year, 7 months ago
I think so too
upvoted 2 times
...
...
Booict
Most Recent 3 months, 1 week ago
Selected Answer: B
B - helps to understand the potential risks and impacts associated with the use of web cameras in the office.
upvoted 1 times
...
03allen
4 months, 2 weeks ago
Selected Answer: B
first to conduct the risk assessment
upvoted 1 times
...
shootnot
6 months, 1 week ago
B- There is no point of C when based on the question, the policy does not allow the use of cameras therefore, no acceptable use policy occurs addressing that. Communicating existing policy would only prohibit the use of cameras.
upvoted 2 times
...
d3fa4d2
7 months ago
Selected Answer: B
I think B. The reason being it's already a violation of policy which means a policy revision should occur. Conduct risk assessment, present it to stake holders, revise policy and publish acceptable use policy after all this.
upvoted 2 times
...
Thavee
7 months ago
Selected Answer: B
employees have been "issued smartphones and tablet computers" with enabled web cameras To my understanding, "issued" was done by the company.
upvoted 1 times
...
Thavee
7 months ago
employees have been issued smartphones and tablet computers with enabled web cameras
upvoted 1 times
...
REHAMAZZAM
9 months, 2 weeks ago
Selected Answer: B
B. Conduct a risk assessment. The information security manager's first course of action should be to conduct a risk assessment to understand the potential security risks and implications associated with the use of smartphones and tablet computers with enabled web cameras in violation of the policy. This assessment will help identify the specific security risks, assess their likelihood and impact, and determine appropriate mitigation measures. Once the risks are understood, the information security manager can then proceed with revising the policy, communicating the acceptable use policy, and performing a root cause analysis as necessary.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: C
C. Communicate the acceptable use policy. Before revising the policy or conducting a risk assessment, it's essential to ensure that employees are aware of the existing policy and the reasons behind it. By communicating the acceptable use policy clearly to employees, including the prohibition of camera use at the office, the manager can help ensure that employees understand the rules and their importance.
upvoted 1 times
...
richck102
1 year, 4 months ago
i vote ....B. Conduct a risk assessment.
upvoted 2 times
...
karanvp
1 year, 4 months ago
Option C may not be correct because “AUP should be communicated before employees have been issued smartphones and tablet computers”
upvoted 1 times
...
Maccaoidh
1 year, 7 months ago
Selected Answer: B
I went with B because the question states the use of cameras in the office, but the users were "issued" the phones and tablets with web enabled cameras. For me, the question did not explicitly state that it was an acceptable use policy that prevent the usage of cameras, could have been a security policy. It sounds to me like new technology was introduced and a risk assessment needs to be conducted.
upvoted 2 times
AlexJacobson
9 months, 3 weeks ago
In two companies I've worked for, prohibiting taking photos or videos inside office premises was defined in AUP.
upvoted 1 times
...
...
it_expert_cism
1 year, 8 months ago
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...