Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISM topic 1 question 224 discussion

Actual exam question from Isaca's CISM
Question #: 224
Topic #: 1
[All CISM Questions]

Which of the following is MOST important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy?

  • A. Impact on the risk profile
  • B. Need for compensating controls
  • C. Time period for review
  • D. Requirements for senior management reporting
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 3 months ago
Selected Answer: A
The most important for an information security manager to communicate to stakeholders when approving exceptions to the information security policy is the impact on the risk profile. This includes the potential risks that may arise from granting the exception, and any potential impact on the confidentiality, integrity, and availability of the organization's data and systems. This information should be communicated in a clear and concise manner, so that stakeholders can understand the implications of the exception and make an informed decision.
upvoted 7 times
...
e891cd1
Most Recent 1 month ago
B..If it's an exception that stakeholders should know the compensation controls so they could know the mitigation process for these risk .
upvoted 1 times
...
Manix
6 months ago
Selected Answer: C
Impact to risk profile and potential compesating controls are already communicated before exception approved. Review period is remaining and best option
upvoted 2 times
...
ImTired
7 months ago
Selected Answer: A
Per Review Manual: "Any such policy exceptions must be assessed for risk and impact prior to implementation and the identified risk accepted by appropriate levels of management."
upvoted 1 times
...
oluchecpoint
7 months, 3 weeks ago
B. Need for compensating controls. Communicating the need for compensating controls ensures that stakeholders understand how the increased risk associated with the exception will be mitigated and helps maintain a reasonable level of security while accommodating specific business needs.
upvoted 3 times
...
wello
10 months, 3 weeks ago
Selected Answer: A
Communicating the impact on the risk profile is crucial because exceptions to the information security policy have the potential to introduce additional risks to the organization. By clearly articulating the impact, the information security manager can help stakeholders understand the potential consequences and make informed decisions regarding the exception.
upvoted 1 times
...
richck102
10 months, 4 weeks ago
B. Need for compensating controls
upvoted 1 times
...
Dravidian
1 year ago
Selected Answer: B
I would think that if they're at the point of approving then they have already past talking about impacts.
upvoted 1 times
...
DelTrotter
1 year, 4 months ago
Selected Answer: A
Risk profile.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...