exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 430 discussion

Actual exam question from Isaca's CISM
Question #: 430
Topic #: 1
[All CISM Questions]

An information security manager has observed multiple exceptions for a number of different security controls. Which of the following should be the information security manager's FIRST course of action?

  • A. Prioritize the risk and implement treatment options
  • B. Report the noncompliance to the board of directors
  • C. Inform respective risk owners of the impact of exceptions
  • D. Design mitigating controls tor the exceptions
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
giovi
Highly Voted 1 year, 8 months ago
C The information security manager's FIRST course of action should be to inform respective risk owners of the impact of exceptions. This is important because the risk owners are responsible for managing the risks associated with the security controls, and they need to be aware of any exceptions to their controls so that they can take appropriate action. Once the risk owners are informed, they can prioritize the risk and implement treatment options, design mitigating controls for the exceptions, and report the noncompliance to the board of directors as necessary. However, informing the risk owners should be the first step in addressing the issue.
upvoted 9 times
...
SHERLOCKAWS
Most Recent 1 month, 2 weeks ago
Selected Answer: C
Answer is C: effective risk management starts with communication and ownership so to ensure the right people understand the risks. in such way informed decisions can be taken.
upvoted 1 times
...
yottabyte
7 months, 4 weeks ago
Selected Answer: C
C is correct as per giovi.
upvoted 1 times
...
haskelatchi
8 months, 3 weeks ago
Selected Answer: D
Correct me if I'm wrong, but wouldn't the risk owner's already be aware of the risk before accepting and hence, an exception is in place? I would vote D
upvoted 1 times
...
jcisco123
10 months, 3 weeks ago
Selected Answer: A
This step is critical as it directly addresses the issue. By prioritizing the risks, the manager can identify which exceptions pose the greatest threat to the organization and address them first. Notifying respective risk owners is an important step, but it's not the first action to take. The immediate concern should be to mitigate the risks.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. Inform respective risk owners of the impact of exceptions Before taking any further steps, it is important to notify the individuals or teams responsible for the risks associated with these exceptions. This helps ensure that all relevant stakeholders are aware of the issues and their potential impact on the organization's security posture. Once the risk owners are informed, you can then proceed to prioritize the risks (option A) and work with them to implement treatment options, and if necessary, design mitigating controls (option D). Reporting to the board of directors (option B) is typically done after the initial assessment and communication with the risk owners.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: C
I would give the respective risk owners a call to inform them of the impact of the exception before designing mitigating controls.
upvoted 1 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
C. Notify the risk owners. Maybe you dont need mitigating controls
upvoted 1 times
...
chanke
1 year, 4 months ago
Selected Answer: C
I would give the respective risk owners a call to inform them of the impact of the exception before designing mitigating controls.
upvoted 1 times
...
richck102
1 year, 4 months ago
i vote....C. Inform respective risk owners of the impact of exceptions
upvoted 1 times
...
Saisharan
1 year, 5 months ago
I'm confused between C and D. Anyone please suggest which is the correct Option.
upvoted 1 times
...
CarlLimps
1 year, 9 months ago
Selected Answer: D
I don't like C for this but can't say it's not right. Part of the risk acceptance process would be to make sure the risk owner knows the impact of the exceptions. So why would you do this AGAIN? I think that D, design mitigating controls..., is the better answer, but not by much.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago