nerdexam
Isaca

CISM · Question #393

A financial institution is planning to introduce a new service that requires the handling of customer data. Which of the following is MOST important for the information security manager to determine?

The correct answer is A. Legal and regulatory requirements related to the types of data to be processed. Legal and regulatory requirements (A) must be determined first because they define the non-negotiable baseline - violating data protection laws (GDPR, HIPAA, PCI-DSS, etc.) can result in fines, sanctions, or loss of operating license, making compliance a foundational constraint…

Submitted by chiamaka_o· Apr 18, 2026Information Security Governance

Question

A financial institution is planning to introduce a new service that requires the handling of customer data. Which of the following is MOST important for the information security manager to determine?

Options

  • ALegal and regulatory requirements related to the types of data to be processed
  • BAdequacy of infrastructure and technical controls to protect customer information
  • CRisk and data privacy reporting requirements for the board
  • DProject funding availability to support information security needs

How the community answered

(57 responses)
  • A
    81% (46)
  • B
    11% (6)
  • C
    2% (1)
  • D
    7% (4)

Explanation

Legal and regulatory requirements (A) must be determined first because they define the non-negotiable baseline - violating data protection laws (GDPR, HIPAA, PCI-DSS, etc.) can result in fines, sanctions, or loss of operating license, making compliance a foundational constraint before any other decisions are made.

Why the distractors fall short:

  • B (Infrastructure/technical controls) - important, but you can't design controls without first knowing what compliance obligations apply to the data type.
  • C (Board reporting requirements) - a governance concern that follows from knowing the regulatory landscape, not a prerequisite to it.
  • D (Project funding) - relevant to project management, but budget questions come after you know what legal obligations must be met.

Memory tip: Think "Law before walls" - you must know the legal requirements before you can build the technical walls to satisfy them. Whenever a question involves a new service handling customer data, regulatory/legal determination always comes first in the security manager's checklist.

Topics

#Legal and Regulatory Compliance#Data Privacy#Information Security Governance#New Service Introduction

Community Discussion

No community discussion yet for this question.

Full CISM Practice