nerdexam
Isaca

CISM · Question #258

Senior management recently approved a mobile access policy that conflicts with industry best practices. Which of the following is the information security manager's BEST course of action when…

The correct answer is B. Align the standards with industry best practices. Security standards are technical documents that define specific, measurable control requirements. They must reflect security best practices to provide adequate protection - they are the 'how' behind good security outcomes. While policy sets organizational direction, a policy…

Submitted by valeria.br· Apr 18, 2026Information Security Governance

Question

Senior management recently approved a mobile access policy that conflicts with industry best practices. Which of the following is the information security manager's BEST course of action when developing security standards for mobile access to the organization's network?

Options

  • AAlign the standards with the organizational policy.
  • BAlign the standards with industry best practices.
  • CResolve the discrepancy before developing the standards.
  • DPerform a cost-benefit analysis of aligning the standards to policy.

How the community answered

(23 responses)
  • A
    22% (5)
  • B
    61% (14)
  • C
    13% (3)
  • D
    4% (1)

Explanation

Security standards are technical documents that define specific, measurable control requirements. They must reflect security best practices to provide adequate protection - they are the 'how' behind good security outcomes. While policy sets organizational direction, a policy that conflicts with industry best practices represents a gap that the security manager has a professional obligation to address. Developing standards that mirror a flawed policy (A) perpetuates inadequate security. Resolving the discrepancy first (C) could indefinitely delay standard development. The correct approach is to develop standards based on best practices while simultaneously escalating and documenting the policy conflict for management's attention.

Topics

#Security Policy#Security Standards#Best Practices#Management Responsibility

Community Discussion

No community discussion yet for this question.

Full CISM Practice