nerdexam
IsacaIsaca

CISM · Question #191

CISM Question #191: Real Exam Question with Answer & Explanation

Sign in or unlock CISM to reveal the answer and full explanation for question #191. The question stem and answer options stay visible for context.

Submitted by minji_kr· Apr 18, 2026Information Security Governance

Question

What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?

Options

  • ARequire department users to repeat security awareness training.
  • BPerform a vulnerability assessment on the systems within the department.
  • CIntroduce additional controls to force compliance with policy.
  • DReport the policy violation to senior management.

Unlock CISM to see the answer

You've previewed enough free CISM questions. Unlock CISM for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Policy compliance#Escalation procedures#Security governance#Non-compliance handling
Full CISM PracticeBrowse All CISM Questions