nerdexam
Isaca

CISM · Question #275

Which of the following is the BEST approach for addressing new regulatory requirements regarding personal data?

The correct answer is C. Treat compliance with the new regulations as any other risk. Treating new regulatory requirements as a risk (C) is correct because it applies the standard risk management lifecycle - identify, assess, prioritize, and respond - allowing the organization to evaluate compliance gaps, weigh the cost of non-compliance against remediation…

Submitted by skyler.x· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the BEST approach for addressing new regulatory requirements regarding personal data?

Options

  • ARecommend that management accept the risk of partial compliance.
  • BMandate regulatory compliance throughout the organization.
  • CTreat compliance with the new regulations as any other risk.
  • DPurchase insurance to minimize noncompliance and reputational risk.

How the community answered

(60 responses)
  • A
    8% (5)
  • B
    13% (8)
  • C
    75% (45)
  • D
    3% (2)

Explanation

Treating new regulatory requirements as a risk (C) is correct because it applies the standard risk management lifecycle - identify, assess, prioritize, and respond - allowing the organization to evaluate compliance gaps, weigh the cost of non-compliance against remediation costs, and allocate resources proportionally. This is the foundational approach endorsed by frameworks like COSO and ISO 31000.

Why the distractors fail:

  • A is wrong because recommending risk acceptance for regulatory non-compliance is premature - you must first assess the full risk before accepting any portion of it, and regulators rarely accept partial compliance as a defense.
  • B is wrong because mandating blanket compliance across the organization skips risk assessment; without prioritization, resources may be misallocated and the approach lacks the nuance to handle varying applicability across business units.
  • D is wrong because insurance transfers only financial exposure - it does not address the underlying compliance obligation, reduce the likelihood of violations, or protect against reputational damage that insurance cannot fully cover.

Memory tip: Think "regulations are risks" - on ISACA/CISA exams, when regulators knock, the answer is almost never "ignore it" (A), "brute-force it" (B), or "pay someone else to care" (D); it's always "run the risk process."

Topics

#Regulatory Compliance#Risk Management#Personal Data Protection

Community Discussion

No community discussion yet for this question.

Full CISM Practice