CISM · Question #15
What should a global information security manager do FIRST when informed that a new regulation with significant impact will go into effect soon?
The correct answer is D. Perform a gap analysis. The first step upon learning of a new significant regulation is to perform a gap analysis to determine current compliance posture against the new requirements.
Question
What should a global information security manager do FIRST when informed that a new regulation with significant impact will go into effect soon?
Options
- APerform a vulnerability assessment.
- BPerform a business impact analysis (BIA).
- CPerform a privacy impact assessment.
- DPerform a gap analysis.
How the community answered
(24 responses)- A8% (2)
- B4% (1)
- C4% (1)
- D83% (20)
Why each option
The first step upon learning of a new significant regulation is to perform a gap analysis to determine current compliance posture against the new requirements.
A vulnerability assessment identifies technical weaknesses, but it does not directly address the organization's compliance posture against new regulatory mandates.
A Business Impact Analysis (BIA) evaluates the potential effects of disruption on critical business functions, which is not the primary immediate concern when a new regulation looms.
A privacy impact assessment (PIA) specifically focuses on privacy risks when processing personal data, which is a subset of a broader regulatory impact and may not cover all aspects of a 'new regulation with significant impact.'
A gap analysis systematically compares the organization's current security policies, controls, and processes against the specific requirements of the new regulation. This identifies precisely what changes are needed to achieve compliance, making it the most logical and efficient first step to address a new regulation with significant impact.
Concept tested: Regulatory compliance gap analysis
Topics
Community Discussion
No community discussion yet for this question.