CISM · Question #141
When updating the information security policy to accommodate a new regulation, the information security manager should FIRST:
The correct answer is D. perform a gap analysis. When updating an information security policy for a new regulation, the information security manager should first perform a gap analysis to identify discrepancies between the current policy and the new regulatory requirements.
Question
When updating the information security policy to accommodate a new regulation, the information security manager should FIRST:
Options
- Areview key risk indicators (KRIs).
- Bconsult process owners.
- Cupdate key performance indicators (KPIs).
- Dperform a gap analysis.
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C11% (3)
- D82% (23)
Why each option
When updating an information security policy for a new regulation, the information security manager should first perform a gap analysis to identify discrepancies between the current policy and the new regulatory requirements.
Reviewing KRIs is a monitoring activity that comes after understanding the impact of the regulation and updating policies/controls.
Consulting process owners is important for implementing changes, but it follows the initial identification of gaps and required changes.
Updating KPIs is a step in measuring the effectiveness of the new policy, which occurs after the policy has been updated and implemented.
Performing a gap analysis is the essential first step because it systematically compares the new regulation against the existing information security policy and controls to identify what changes are needed to achieve compliance. This analysis reveals specific areas where the current policy is insufficient or where new controls must be implemented to meet the regulatory mandates.
Concept tested: Regulatory compliance and gap analysis
Topics
Community Discussion
No community discussion yet for this question.