nerdexam
Isaca

CISM · Question #396

An information security manager discovers that the organization's new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern…

The correct answer is C. The corresponding controls are viewed as prohibitive to business operations. The greatest concern is when the corresponding controls of the information security policy are viewed as prohibitive to business operations. If employees and departments perceive security controls as obstacles to their work, they are less likely to follow the policy. This…

Submitted by certguy· Apr 18, 2026Information Security Program Development and Management

Question

An information security manager discovers that the organization's new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern to the information security manager?

Options

  • ABusiness unit management has not emphasized the importance of the related controls.
  • BThe wording of the policy is not tailored to the audience.
  • CThe corresponding controls are viewed as prohibitive to business operations.
  • DDifferent communication methods may be required for each business unit.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    69% (18)
  • D
    19% (5)

Explanation

The greatest concern is when the corresponding controls of the information security policy are viewed as prohibitive to business operations. If employees and departments perceive security controls as obstacles to their work, they are less likely to follow the policy. This indicates a need to re-evaluate the policy's practicality and relevance to the business's needs while ensuring security objectives are met.

Topics

#Policy compliance#Business alignment#Control effectiveness#Operational impact

Community Discussion

No community discussion yet for this question.

Full CISM Practice