nerdexam
CompTIA

CAS-003 · Question #203

A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the…

The correct answer is A. How the large business operational procedures are implemented. C. New regulatory compliance requirements. During an IT integration following an acquisition, the smaller company's IT staff needs to focus on what will change for them operationally and legally. Option A is critical because the staff must understand how the larger organization's operational procedures, security…

Risk Management

Question

A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the large business will retain 95% of the smaller business' IT staff. Additionally, the larger business has a strong interest in specific processes that the smaller business has in place to handle its regional interests. Which of the following IT security related objectives should the small business' IT staff consider reviewing during the integration process? (Select TWO).

Options

  • AHow the large business operational procedures are implemented.
  • BThe memorandum of understanding between the two businesses.
  • CNew regulatory compliance requirements.
  • DService level agreements between the small and the large business.
  • EThe initial request for proposal drafted during the merger.
  • FThe business continuity plan in place at the small business.

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    11% (5)
  • D
    4% (2)
  • E
    2% (1)
  • F
    2% (1)

Explanation

During an IT integration following an acquisition, the smaller company's IT staff needs to focus on what will change for them operationally and legally. Option A is critical because the staff must understand how the larger organization's operational procedures, security policies, and standards are implemented in order to align their work and avoid conflicts. Option C is equally important because the combined entity may now fall under different or additional regulatory frameworks - for example, the larger company may operate in regulated industries or geographies with compliance requirements (e.g., PCI DSS, HIPAA, SOX) that did not previously apply to the smaller company. The MOU (B) and initial RFP (E) are historical artifacts with limited operational relevance post-acquisition. SLAs (D) between the two entities are typically superseded after full integration. Reviewing only the old BCP (F) without updating it for the new environment is insufficient.

Topics

#mergers and acquisitions#regulatory compliance#IT integration#operational procedures

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice