nerdexam
Isaca

CISM · Question #318

Which of the following should an information security manager do FIRST when a security standard hinders the achievement of an identified business objective?

Sign in or unlock CISM to reveal the answer and full explanation for question #318. The question stem and answer options stay visible for context.

Submitted by minji_kr· Apr 18, 2026Information Security Governance

Question

Which of the following should an information security manager do FIRST when a security standard hinders the achievement of an identified business objective?

Options

  • ARecommend risk acceptance.
  • BRevisit the business objective.
  • CConduct a business impact analysis (BIA).
  • DPerform a cost-benefit analysis.

Unlock CISM to see the answer

You've previewed enough free CISM questions. Unlock CISM for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Security-business alignment#Business objectives#Security standards#Governance
Full CISM Practice