exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 692 discussion

Actual exam question from Isaca's CISM
Question #: 692
Topic #: 1
[All CISM Questions]

Which of the following is the BEST approach for governing noncompliance with security requirements?

  • A. Require users to acknowledge the acceptable use policy
  • B. Base mandatory review and exception approvals on residual risk
  • C. Require the steering committee to review exception requests
  • D. Base mandatory review and exception approvals on inherent risk
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pichon
2 months, 3 weeks ago
Selected Answer: B
not all exceptions need committee-level review. Instead, decisions should be risk-based and handled at the appropriate level.
upvoted 2 times
...
REHAMAZZAM
10 months ago
Selected Answer: C
C. Require the steering committee to review exception requests The best approach for governing noncompliance with security requirements is to require the steering committee to review exception requests. The steering committee typically consists of senior executives who have the authority to set strategic direction and allocate resources for risk management initiatives. By involving the steering committee in the review of exception requests, the organization ensures that decisions regarding noncompliance are made at a high level of governance, taking into account strategic objectives, risk tolerance, and potential impacts on the organization. While options A, B, and D may also play a role in governing noncompliance, involving the steering committee provides the highest level of oversight and ensures alignment with organizational priorities.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: B
B. Base mandatory review and exception approvals on residual risk. Residual risk is the risk that remains after security controls have been implemented. It takes into account the effectiveness of existing controls and provides a more accurate representation of the actual risk an organization faces.
upvoted 2 times
...
richck102
1 year, 5 months ago
B. Base mandatory review and exception approvals on residual risk
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: B
Simply requiring users to acknowledge the acceptable use policy (option A) may help establish awareness of security requirements, but it does not directly address noncompliance or the associated risks. Requiring the steering committee to review exception requests (option C) may introduce delays in the decision-making process, which could impact operational efficiency. Basing mandatory review and exception approvals on inherent risk (option D) does not take into account the effectiveness of implemented controls or the actual level of risk present in the organization. By considering residual risk, the organization can prioritize its efforts, allocate resources effectively, and focus on addressing noncompliance with security requirements in a manner that aligns with its risk management strategy.
upvoted 2 times
...
mad68
1 year, 6 months ago
Selected Answer: B
B. Base mandatory review and exception approvals on residual risk. When it comes to noncompliance with security requirements, it is important to assess the associated risks and determine the appropriate course of action. By basing mandatory review and exception approvals on residual risk, organizations can make informed decisions regarding non-compliance.
upvoted 2 times
...
meelaan
1 year, 7 months ago
Selected Answer: C
Why not C?
upvoted 2 times
...
Souvik124
1 year, 9 months ago
The BEST approach for governing noncompliance with security requirements is to base mandatory review and exception approvals on residual risk.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...