nerdexam
Isaca

CGEIT · Question #129

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should

The correct answer is B. Obtain senior management input based on identified risk.. When a zero-tolerance security policy causes significant business disruption, the first governance step is to obtain senior management input, informed by identified risks and impacts, to collectively re-evaluate and adjust the policy.

Submitted by saadiq_pk· Apr 18, 2026Governance of Enterprise IT

Question

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?

Options

  • ADirect the development of an em il usage policy.
  • BObtain senior management input based on identified risk.
  • CRecommend business sign-off on the zero-tolerance policy.
  • DIntroduce an exception process.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    70% (14)
  • C
    10% (2)
  • D
    15% (3)

Why each option

When a zero-tolerance security policy causes significant business disruption, the first governance step is to obtain senior management input, informed by identified risks and impacts, to collectively re-evaluate and adjust the policy.

ADirect the development of an em il usage policy.

Directing the development of an email usage policy is a tactical action that comes after senior management has provided guidance on how to balance security and usability.

BObtain senior management input based on identified risk.Correct

A zero-tolerance policy, especially one causing significant business disruption, indicates a potential imbalance between security and operational efficiency. The initial governance step involves presenting the identified risks (disruption, productivity loss) to senior management to gain their perspective and secure their collective decision on whether to modify the policy or accept the business impact. This ensures that any policy adjustment is aligned with the enterprise's overall risk appetite and strategic objectives.

CRecommend business sign-off on the zero-tolerance policy.

Recommending business sign-off on the existing zero-tolerance policy doesn't address the current disruption; it merely reinforces the problematic policy without seeking resolution.

DIntroduce an exception process.

Introducing an exception process is a potential solution, but it's a tactical implementation detail that should only be considered after senior management has acknowledged the issue and approved a strategic direction for addressing the policy's impact.

Concept tested: IT governance for security policy balancing

Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-introduction-and-methodology/chapter-3/enabling-principles-for-governance-and-management

Topics

#Governance#Risk Appetite#Policy Management#Senior Management Oversight

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice