CISM · Question #191
What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?
The correct answer is D. Report the policy violation to senior management.. The next course of action when an information security manager has identified a department that is repeatedly not following the security policy should be to report the policy violation to senior management. Senior management needs to be informed of the repeated non-compliance so
Question
What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?
Options
- ARequire department users to repeat security awareness training.
- BPerform a vulnerability assessment on the systems within the department.
- CIntroduce additional controls to force compliance with policy.
- DReport the policy violation to senior management.
How the community answered
(54 responses)- A13% (7)
- B4% (2)
- C7% (4)
- D76% (41)
Explanation
The next course of action when an information security manager has identified a department that is repeatedly not following the security policy should be to report the policy violation to senior management. Senior management needs to be informed of the repeated non-compliance so they can address the issue at the appropriate level and ensure the department takes corrective
Topics
Community Discussion
No community discussion yet for this question.