Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISM topic 1 question 119 discussion

Actual exam question from Isaca's CISM
Question #: 119
Topic #: 1
[All CISM Questions]

During a security assessment, an information security manager finds a number of security patches were not installed on a server hosting a critical business application. The application owner did not approve the patch installation to avoid interrupting the application. Which of the following should be the information security manager's FIRST course of action?

  • A. Report the risk to the information security steering committee.
  • B. Determine mitigation options with IT management.
  • C. Communicate the potential impact to the application owner.
  • D. Escalate the risk to senior management.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
oluchecpoint
2 months, 2 weeks ago
Selected Answer: C
C. Communicate the potential impact to the application owner. It's crucial to engage with the application owner and communicate the potential security risks and impact of not installing the necessary patches. This step allows for a collaborative discussion to find a solution that balances security and business continuity concerns. The application owner may not be fully aware of the security implications, so providing them with this information is essential. Depending on the outcome of this communication, further actions such as reporting to the information security steering committee, working with IT management on mitigation options, or escalating to senior management may be considered, but it's important to involve the relevant stakeholders first to reach a consensus and make an informed decision.
upvoted 1 times
...
oluchecpoint
7 months, 3 weeks ago
C. Communicate the potential impact to the application owner. It's crucial to engage with the application owner and communicate the potential security risks and impact of not installing the necessary patches. This step allows for a collaborative discussion to find a solution that balances security and business continuity concerns. The application owner may not be fully aware of the security implications, so providing them with this information is essential. Depending on the outcome of this communication, further actions such as reporting to the information security steering committee, working with IT management on mitigation options, or escalating to senior management may be considered, but it's important to involve the relevant stakeholders first to reach a consensus and make an informed decision.
upvoted 1 times
...
DavoA
9 months ago
Selected Answer: C
You need to speak to the business owner but anyone else
upvoted 1 times
...
DASH_v
11 months ago
Selected Answer: C
Simple, in a real world, you talk to your colleagus first before esclation. Unless, you don't care the relationship at all, how possible?
upvoted 3 times
[Removed]
10 months ago
but the app owner knows the impact and still hasnt approved the patch
upvoted 2 times
...
...
richck102
11 months ago
Selected Answer: B
B. Determine mitigation options with IT management.
upvoted 1 times
seric01
1 month, 2 weeks ago
Agree, app owner knows the impact and still hasnt approved the patch, now we must mitigate
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...