CAS-002 · Question #259
A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the…
The correct answer is A. How the large business operational procedures are implemented. C. New regulatory compliance requirements. Integrating IT staff must learn the acquiring company's operational procedures and identify any new regulatory compliance obligations introduced by the merger.
Question
A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the large business will retain 95% of the smaller business' IT staff. Additionally, the larger business has a strong interest in specific processes that the smaller business has in place to handle its regional interests. Which of the following IT security related objectives should the small business' IT staff consider reviewing during the integration process? (Select TWO).
Options
- AHow the large business operational procedures are implemented.
- BThe memorandum of understanding between the two businesses.
- CNew regulatory compliance requirements.
- DService level agreements between the small and the large business.
- EThe initial request for proposal drafted during the merger.
- FThe business continuity plan in place at the small business.
How the community answered
(57 responses)- A75% (43)
- B4% (2)
- D2% (1)
- E14% (8)
- F5% (3)
Why each option
Integrating IT staff must learn the acquiring company's operational procedures and identify any new regulatory compliance obligations introduced by the merger.
Understanding how the large business implements its operational procedures is essential so incoming IT staff can align their work practices, tooling, and processes with the parent organization's established standards and avoid operational conflicts.
A memorandum of understanding defines the general intentions and commitments of both parties but is a high-level business agreement, not an actionable IT security operational concern for integrating staff.
Merging with a larger international business may introduce new regulatory compliance requirements - such as GDPR, HIPAA, or SOX - that the small business was not previously subject to, making it critical for IT staff to identify and address these obligations during integration.
Service level agreements between the two businesses define performance expectations and responsibilities but are contractual and commercial matters, not IT security objectives that staff must review during technical integration.
The initial request for proposal drafted during the merger is a procurement document used to solicit vendor bids and is irrelevant to the IT security integration objectives of the onboarding staff.
Reviewing the small business's existing business continuity plan is an internal operational task, not specifically an IT security objective that arises directly from integrating into the larger acquiring organization.
Concept tested: IT security considerations during merger and acquisition integration
Topics
Community Discussion
No community discussion yet for this question.