nerdexam
Isaca

CISM · Question #141

When updating the information security policy to accommodate a new regulation, the information security manager should FIRST:

The correct answer is D. perform a gap analysis. When updating an information security policy for a new regulation, the information security manager should first perform a gap analysis to identify discrepancies between the current policy and the new regulatory requirements.

Submitted by chen.hong· Apr 18, 2026Information Security Program Development and Management

Question

When updating the information security policy to accommodate a new regulation, the information security manager should FIRST:

Options

  • Areview key risk indicators (KRIs).
  • Bconsult process owners.
  • Cupdate key performance indicators (KPIs).
  • Dperform a gap analysis.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    11% (3)
  • D
    82% (23)

Why each option

When updating an information security policy for a new regulation, the information security manager should first perform a gap analysis to identify discrepancies between the current policy and the new regulatory requirements.

Areview key risk indicators (KRIs).

Reviewing KRIs is a monitoring activity that comes after understanding the impact of the regulation and updating policies/controls.

Bconsult process owners.

Consulting process owners is important for implementing changes, but it follows the initial identification of gaps and required changes.

Cupdate key performance indicators (KPIs).

Updating KPIs is a step in measuring the effectiveness of the new policy, which occurs after the policy has been updated and implemented.

Dperform a gap analysis.Correct

Performing a gap analysis is the essential first step because it systematically compares the new regulation against the existing information security policy and controls to identify what changes are needed to achieve compliance. This analysis reveals specific areas where the current policy is insufficient or where new controls must be implemented to meet the regulatory mandates.

Concept tested: Regulatory compliance and gap analysis

Topics

#Policy management#Regulatory compliance#Gap analysis#Security program management

Community Discussion

No community discussion yet for this question.

Full CISM Practice