nerdexam
Isaca

CGEIT · Question #264

A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT

The correct answer is B. Request an IT security assessment to identify the main security gaps.. When experiencing numerous security incidents, the IT governance board's first action should be to understand the root causes by identifying current security gaps.

Submitted by javi_es· Apr 18, 2026Governance of Enterprise IT

Question

A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?

Options

  • ARequire revisions to how security incidents are managed by the IT department.
  • BRequest an IT security assessment to identify the main security gaps.
  • CExecute an IT maturity assessment of the security process.
  • DMandate an update to the enterprise's IT security policy.

How the community answered

(46 responses)
  • A
    22% (10)
  • B
    63% (29)
  • C
    4% (2)
  • D
    11% (5)

Why each option

When experiencing numerous security incidents, the IT governance board's first action should be to understand the root causes by identifying current security gaps.

ARequire revisions to how security incidents are managed by the IT department.

Revising incident management without understanding the underlying security gaps might address symptoms but not the root cause, leading to continued incidents.

BRequest an IT security assessment to identify the main security gaps.Correct

Before prescribing solutions or updating policies, it is crucial to understand the extent and nature of the security weaknesses contributing to the incidents. Requesting an IT security assessment will provide the necessary data to identify specific vulnerabilities and gaps, enabling informed decision-making for remediation.

CExecute an IT maturity assessment of the security process.

An IT maturity assessment evaluates the sophistication of processes, but first identifying critical security gaps and vulnerabilities provides more immediate actionable insights into the *current* incident problem.

DMandate an update to the enterprise's IT security policy.

Mandating a policy update without a clear understanding of the existing gaps and how they relate to policy deficiencies may result in ineffective changes and doesn't directly address the immediate incident problem.

Concept tested: IT Governance Incident Response Prioritization

Source: https://www.iso.org/standard/27001.html

Topics

#IT Governance#Information Security#Risk Management#Strategic Assessment

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice