exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 529 discussion

Actual exam question from Isaca's CISM
Question #: 529
Topic #: 1
[All CISM Questions]

What is the PRIMARY objective of information security involvement in the change management process?

  • A. To narrow the threat landscape
  • B. To ensure changes are not applied without prior authorization
  • C. To reduce the likelihood of control failure
  • D. To meet obligations for regulatory and legal compliance
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dravidian
Highly Voted 2 years ago
Selected Answer: C
I am split between B and C but going with C. Making sure changes are not implemented without authorization is the the primary purpose of the whole change management process and everyone involved. The question specifically asks what the PRIMARY objective of IT security is in the process and to me that is not necessarily about work authorization but making sure the behavior of the controls we have in place are not influenced by the change.
upvoted 7 times
...
afb4b17
Most Recent 11 months ago
Selected Answer: B
A good change management process includes a segregation between development, testing and operational. In the testing phase you check all requirements and security controls you want to have.
upvoted 3 times
...
AlexJacobson
1 year, 3 months ago
Selected Answer: C
CISM Exam Prep Guide (2nd ed.), p159: "For effective change management, it is important that the security team be apprised of every major change. It is recommended to include representation from the security team on the change control board. This will ensure that security aspects are considered for any change." So C seems most correct to me here, although I'm also torn between B and C.
upvoted 3 times
...
romaso82
1 year, 4 months ago
C for me
upvoted 1 times
...
Marcovic00
1 year, 6 months ago
Selected Answer: A
I go for A, changes can introduce new vulnerabilities even without compromise to existing controls
upvoted 1 times
...
richck102
1 year, 10 months ago
C. To reduce the likelihood of control failure
upvoted 1 times
...
it_expert_cism
2 years, 2 months ago
C is most suitable
upvoted 2 times
...
Souvik124
2 years, 3 months ago
The PRIMARY objective of information security involvement in the change management process is to reduce the likelihood of control failure. By having information security involved in the change management process, it can ensure that changes are implemented in a controlled and secure manner, minimizing the risk of unexpected outcomes or failures that could result in security breaches or other negative impacts. This involves assessing the security impact of proposed changes, ensuring that proper security controls are in place, and verifying that the changes have been implemented as planned.
upvoted 4 times
...
Broesweelies
2 years, 3 months ago
Selected Answer: D
The primary objective of information security involvement in the change management process is to meet obligations for regulatory and legal compliance because the change management process must ensure that changes to the information systems are made in accordance with legal and regulatory requirements. This helps to maintain the confidentiality, integrity, and availability of sensitive information, and reduces the risk of data breaches, unauthorized access, and other security incidents. By ensuring that changes are made in a controlled and authorized manner, information security can help organizations to meet their obligations under various regulations, such as the General Data Protection Regulation (GDPR) and the Payment Card Industry Data Security Standard (PCI DSS).
upvoted 1 times
...
aokisan
2 years, 4 months ago
Selected Answer: C
objective is to reduce the failure.
upvoted 3 times
...
Ziggybooboo
2 years, 5 months ago
C for me
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago