Isaca Certified Information Security Manager CISM Question # 12 Topic 2 Discussion

Isaca Certified Information Security Manager CISM Question # 12 Topic 2 Discussion

CISM Exam Topic 2 Question 12 Discussion:
Question #: 12
Topic #: 2

What should be an information security manager’s FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?


A.

Report the noncompliance to senior management.


B.

Assess the risk of noncompliance.


C.

Activate the incident response plan.


D.

Evaluate possible compensating controls.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.