CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 404


A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?

Show Answer
Correct Answer: AD

The best next step for a newly appointed information security manager is to gain an understanding of the current business direction. This understanding is crucial because it helps align the security policies and procedures with the organization's objectives, strategies, and potential changes in the business environment. Updating policies and procedures without understanding the business context may result in misaligned security measures, which could impede business operations or fail to address new and emerging risks effectively.

Discussion

14 comments
Sign in to comment
aokisanOption: C
Dec 18, 2022

maybe assess current risk.

BroesweeliesOption: A
Feb 7, 2023

Risk assessement is important but its probably A.

CarlLimpsOption: A
Feb 12, 2023

I really like A here. o gain an understanding of the current business direction. I agree, how do you acces culture and have it impact your procedures? Need a clear understanding of the business to know what policies and procedures to update.

richck102Option: A
Jun 19, 2023

A. To gain an understanding of the current business direction

MyKasalaOption: A
Jan 11, 2023

I think A

Michi23Option: A
Jan 11, 2023

A makes more sense, how would you assess culture?

CarlPTY07Option: A
Mar 8, 2023

A, This is the first step.

meelaanOption: A
Apr 6, 2023

Its A only

welloOption: A
Jun 9, 2023

As a newly appointed Security Manager, I would get an understanding of the current business direction.

karanvpOption: D
Jun 21, 2023

If 5 years static means the people doesn't prefer changes. Hence culture should be understand first before change.

GoseuOption: A
Jul 11, 2023

I would suggest A , then perform gap analysis and risk assessment .

AgamennoreOption: A
Aug 26, 2023

Business direction is the first step for new entries

oluchecpointOption: A
Mar 7, 2024

A. To gain an understanding of the current business direction

afb4b17Option: D
Jun 15, 2024

" to gain" of answer A is too non-binding. " To access" gives more certainty that it will lead to good outcomes. As manager you want the best possible solution.