nerdexam
Isaca

CISM · Question #252

Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?

The correct answer is D. Information security policy. The document that should be updated first to account for new regulatory requirements impacting current information security controls is the information security policy. The information security policy provides the overarching framework and guidelines for security controls and pra

Submitted by ahmad_uae· Apr 18, 2026Information Security Governance

Question

Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?

Options

  • AControl matrix
  • BBusiness impact analysis (BIA)
  • CRisk register
  • DInformation security policy

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    13% (5)
  • D
    79% (31)

Explanation

The document that should be updated first to account for new regulatory requirements impacting current information security controls is the information security policy. The information security policy provides the overarching framework and guidelines for security controls and practices within the organization. Updating it ensures that all subsequent documents, including control matrices, risk registers, and BIAs, align with the new regulatory requirements.

Topics

#Regulatory Compliance#Information Security Policy#Governance#Policy Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice