Isaca Certified Information Security Manager CISM Question # 278 Topic 28 Discussion

Isaca Certified Information Security Manager CISM Question # 278 Topic 28 Discussion

CISM Exam Topic 28 Question 278 Discussion:
Question #: 278
Topic #: 28

Which of the following should an information security manager do FIRST when noncompliance with security standards is identified?


A.

Report the noncompliance to senior management.


B.

Validate the noncompliance.


C.

Include the noncompliance in the risk register.


D.

Implement compensating controls to mitigate the noncompliance.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.