An information security manager discovers that the organization's new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern to the information security manager?
A.
Business unit management has not emphasized the importance of the new policy.
B.
Different communication methods may be required for each business unit.
C.
The wording of the policy is not tailored to the audience.
D.
The corresponding controls are viewed as prohibitive to business operations.
D. The corresponding controls are viewed as prohibitive to business operations.
When an organization's new information security policy is not being followed across all departments, the greatest concern for an information security manager should be that the controls outlined in the policy are viewed as prohibitive to business operations. This indicates a significant disconnect between the security measures and practical business functions, suggesting that the security controls may be overly restrictive, poorly designed, or not well integrated with current business processes.
This is a critical concern because if security controls hinder business operations, it leads to a higher likelihood of non-compliance as departments might bypass or ignore these controls to meet business objectives. Such behavior can expose the organization to risks and vulnerabilities that the policy intends to mitigate.
Remember that when creating this policy in the first place the ISM should put alignment with business needs at the top of their agenda.
For him to be told that it isn't aligning or supporting the needs of the business would be of great concern.
D.
This is the greatest concern because if employees perceive the security controls as overly burdensome and detrimental to their ability to perform their jobs efficiently, they may be less likely to follow the policy. Balancing security with operational efficiency is essential to ensure that security policies are both effective and practical.
D: Seems to be the answer and my reason is because most of the time the business unit do not lay emphasis on the security policy because they look at security policy as burdesome and interfere to their business flow.
A. Business unit management has not emphasized the importance of the new policy.
Explanation: Among the options provided, the greatest concern for the information security manager should be that business unit management has not emphasized the importance of the new policy. It is crucial for management to demonstrate support and commitment to the information security policy for it to be effectively implemented and followed throughout the organization.
A. Business unit management has not emphasized the importance of the new policy.
If the new information security policy is not being followed across all departments, it suggests that there is a lack of support from business unit management in enforcing the policy.
Business unit management has not emphasized the importance of the new policy should be of greatest concern to the information security manager when discovering that the organization's new information security policy is not being followed across all departments.
If the new information security policy is not being followed across all departments, it may indicate that the corresponding controls are viewed as burdensome or restrictive to business operations. This means that the users and employees do not see the value in following the policy and controls, and therefore they do not adhere to them. This can create significant security risks, as the organization's sensitive data and systems may be left unprotected.
the question is looking at the greatest concern from a security perspective which would be D in this case
upvoted 2 times
...
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
helg420
7 months, 3 weeks agoAaronS1990
1 year, 3 months agooluchecpoint
1 year, 4 months agopc2502
1 year, 4 months agoTeesmd
1 year, 5 months agojennarink13
1 year, 6 months agoJae_kes
1 year, 6 months ago[Removed]
1 year, 6 months agorichck102
1 year, 7 months agoAbhey
1 year, 8 months agobambs
1 year, 9 months agoBroesweelies
1 year, 11 months agoProspect57
1 year, 11 months agoRowlandmarc
1 year, 10 months ago