nerdexam
Isaca

CISM · Question #376

An information security manager identifies deficiencies in the organization's vulnerability management program. Which of the following is the MOST important consideration when preparing to update…

The correct answer is D. Engaging key stakeholders for feedback. The most important consideration when preparing to update vulnerability management processes is engaging key stakeholders for feedback. This ensures that the updated processes align with business needs, address relevant concerns, and have the necessary support from those…

Submitted by the_admin· Apr 18, 2026Information Security Program Development and Management

Question

An information security manager identifies deficiencies in the organization's vulnerability management program. Which of the following is the MOST important consideration when preparing to update the related processes?

Options

  • AIdentifying and updating any missing systems in the asset management tool.
  • BMandating vulnerability management training.
  • CDeveloping a new vulnerability management policy based on an industry-standard framework.
  • DEngaging key stakeholders for feedback.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    8% (2)
  • D
    75% (18)

Explanation

The most important consideration when preparing to update vulnerability management processes is engaging key stakeholders for feedback. This ensures that the updated processes align with business needs, address relevant concerns, and have the necessary support from those responsible for execution and decision-making.

Topics

#Vulnerability Management Program#Process Improvement#Stakeholder Engagement#Change Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice