nerdexam
Isaca

CISM · Question #191

What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?

The correct answer is D. Report the policy violation to senior management.. The next course of action when an information security manager has identified a department that is repeatedly not following the security policy should be to report the policy violation to senior management. Senior management needs to be informed of the repeated non-compliance so

Submitted by minji_kr· Apr 18, 2026Information Security Governance

Question

What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?

Options

  • ARequire department users to repeat security awareness training.
  • BPerform a vulnerability assessment on the systems within the department.
  • CIntroduce additional controls to force compliance with policy.
  • DReport the policy violation to senior management.

How the community answered

(54 responses)
  • A
    13% (7)
  • B
    4% (2)
  • C
    7% (4)
  • D
    76% (41)

Explanation

The next course of action when an information security manager has identified a department that is repeatedly not following the security policy should be to report the policy violation to senior management. Senior management needs to be informed of the repeated non-compliance so they can address the issue at the appropriate level and ensure the department takes corrective

Topics

#Policy compliance#Escalation procedures#Security governance#Non-compliance handling

Community Discussion

No community discussion yet for this question.

Full CISM Practice