exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 122 discussion

Actual exam question from Isaca's CISM
Question #: 122
Topic #: 1
[All CISM Questions]

An information security manager discovers that the organization's new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern to the information security manager?

  • A. Business unit management has not emphasized the importance of the new policy.
  • B. Different communication methods may be required for each business unit.
  • C. The wording of the policy is not tailored to the audience.
  • D. The corresponding controls are viewed as prohibitive to business operations.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
helg420
7 months, 3 weeks ago
Selected Answer: D
D. The corresponding controls are viewed as prohibitive to business operations. When an organization's new information security policy is not being followed across all departments, the greatest concern for an information security manager should be that the controls outlined in the policy are viewed as prohibitive to business operations. This indicates a significant disconnect between the security measures and practical business functions, suggesting that the security controls may be overly restrictive, poorly designed, or not well integrated with current business processes. This is a critical concern because if security controls hinder business operations, it leads to a higher likelihood of non-compliance as departments might bypass or ignore these controls to meet business objectives. Such behavior can expose the organization to risks and vulnerabilities that the policy intends to mitigate.
upvoted 1 times
...
AaronS1990
1 year, 3 months ago
Selected Answer: D
Remember that when creating this policy in the first place the ISM should put alignment with business needs at the top of their agenda. For him to be told that it isn't aligning or supporting the needs of the business would be of great concern.
upvoted 3 times
...
oluchecpoint
1 year, 4 months ago
D. This is the greatest concern because if employees perceive the security controls as overly burdensome and detrimental to their ability to perform their jobs efficiently, they may be less likely to follow the policy. Balancing security with operational efficiency is essential to ensure that security policies are both effective and practical.
upvoted 2 times
...
pc2502
1 year, 4 months ago
D seems the right answer as a manager , I'll be more worried if D is the case and thats is the question what will be more concerning
upvoted 1 times
...
Teesmd
1 year, 5 months ago
Selected Answer: D
D: Seems to be the answer and my reason is because most of the time the business unit do not lay emphasis on the security policy because they look at security policy as burdesome and interfere to their business flow.
upvoted 2 times
...
jennarink13
1 year, 6 months ago
D. Agree with Broesweelies
upvoted 2 times
...
Jae_kes
1 year, 6 months ago
Selected Answer: A
A. Business unit management has not emphasized the importance of the new policy. Explanation: Among the options provided, the greatest concern for the information security manager should be that business unit management has not emphasized the importance of the new policy. It is crucial for management to demonstrate support and commitment to the information security policy for it to be effectively implemented and followed throughout the organization.
upvoted 2 times
[Removed]
1 year, 6 months ago
chatgpt is wrong
upvoted 2 times
...
...
richck102
1 year, 7 months ago
D. The corresponding controls are viewed as prohibitive to business operations.
upvoted 2 times
...
Abhey
1 year, 8 months ago
Selected Answer: A
A. Business unit management has not emphasized the importance of the new policy. If the new information security policy is not being followed across all departments, it suggests that there is a lack of support from business unit management in enforcing the policy.
upvoted 1 times
...
bambs
1 year, 9 months ago
Selected Answer: A
Business unit management has not emphasized the importance of the new policy should be of greatest concern to the information security manager when discovering that the organization's new information security policy is not being followed across all departments.
upvoted 2 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: D
If the new information security policy is not being followed across all departments, it may indicate that the corresponding controls are viewed as burdensome or restrictive to business operations. This means that the users and employees do not see the value in following the policy and controls, and therefore they do not adhere to them. This can create significant security risks, as the organization's sensitive data and systems may be left unprotected.
upvoted 4 times
...
Prospect57
1 year, 11 months ago
B was my answer. This question was kind of hard for me to follow. In case anyone else may be struggling with this one.
upvoted 1 times
Rowlandmarc
1 year, 10 months ago
the question is looking at the greatest concern from a security perspective which would be D in this case
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...