nerdexam
Isaca

CGEIT · Question #572

Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?

The correct answer is A. IT policies and procedures that need revision. When assessing new external regulations for IT compliance, the first consideration should be identifying which existing IT policies and procedures require revision to align with the new requirements.

Submitted by rohit_dlh· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?

Options

  • AIT policies and procedures that need revision
  • BResource burden for implementation
  • CGaps in skills and experience of IT employees
  • DImpact on contracts with service providers

How the community answered

(39 responses)
  • A
    82% (32)
  • B
    3% (1)
  • C
    10% (4)
  • D
    5% (2)

Why each option

When assessing new external regulations for IT compliance, the first consideration should be identifying which existing IT policies and procedures require revision to align with the new requirements.

AIT policies and procedures that need revisionCorrect

When new external regulations impact IT compliance, the initial step is to understand how these regulations will affect the enterprise's existing operational framework. This means identifying which current IT policies and procedures are no longer adequate or need to be updated to meet the new legal and regulatory obligations, forming the basis for subsequent actions.

BResource burden for implementation

While the resource burden for implementation is important, it's a subsequent consideration *after* understanding what changes are needed to policies and procedures.

CGaps in skills and experience of IT employees

Gaps in skills and experience are important for implementation planning but come after the foundational assessment of policy and procedure alignment.

DImpact on contracts with service providers

The impact on contracts with service providers is a critical consideration but typically follows the initial assessment of internal policy alignment, as it dictates what contractual changes might be necessary.

Concept tested: Regulatory impact assessment on IT policies

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-areas/governance-risk-compliance

Topics

#IT Compliance#Regulatory Impact Assessment#Policy Management#Governance Framework

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice