nerdexam
Isaca

CISM · Question #188

A chief information officer (CIO) recently approved remote access from a system administrator's home as an exception to the security policy. What would be the information security manager's BEST cours

The correct answer is C. Review the policy on remote access security and recommend changes.. The information security manager's best course of action would be to review the policy on remote access security and recommend changes. This approach allows for a reassessment of the current security policy in light of the exception, ensuring that appropriate controls are in plac

Submitted by renata2k· Apr 18, 2026Information Security Governance

Question

A chief information officer (CIO) recently approved remote access from a system administrator's home as an exception to the security policy. What would be the information security manager's BEST course of action?

Options

  • AInform management of the risks involved and disable the administrator's access.
  • BEnsure the system administrator is aware of the risks and monitor remote access.
  • CReview the policy on remote access security and recommend changes.
  • DRegister a formal security incident and escalate to the steering committee.

How the community answered

(35 responses)
  • A
    23% (8)
  • B
    6% (2)
  • C
    57% (20)
  • D
    14% (5)

Explanation

The information security manager's best course of action would be to review the policy on remote access security and recommend changes. This approach allows for a reassessment of the current security policy in light of the exception, ensuring that appropriate controls are in place to mitigate any associated risks while aligning with the new operational needs.

Topics

#Policy Management#Policy Exceptions#Information Security Governance#Continuous Improvement

Community Discussion

No community discussion yet for this question.

Full CISM Practice