nerdexam
Isaca

CISM · Question #4

A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?

The correct answer is D. Standards. To address non-uniform user account setup, the information security manager should review standards, as they provide mandatory requirements for consistent configuration.

Submitted by daniela_cl· Apr 18, 2026Information Security Program Development and Management

Question

A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?

Options

  • ASecurity policies
  • BAutomated controls
  • CGuidelines
  • DStandards

How the community answered

(52 responses)
  • A
    12% (6)
  • B
    4% (2)
  • C
    6% (3)
  • D
    79% (41)

Why each option

To address non-uniform user account setup, the information security manager should review standards, as they provide mandatory requirements for consistent configuration.

ASecurity policies

Security policies are high-level statements of intent and objectives, providing the "what" and "why," but typically lack the specific, mandatory instructions for uniform setup.

BAutomated controls

Automated controls are implementations of policies and standards, but reviewing the controls themselves without understanding the underlying documentation might not fix the root cause of non-uniformity.

CGuidelines

Guidelines offer recommendations and best practices, which are helpful but not mandatory and thus do not enforce uniformity as effectively as standards.

DStandardsCorrect

Standards specify mandatory, repeatable actions and configurations that ensure consistency, like a uniform user account setup, making them the most critical document to review when non-uniformity is discovered. Adherence to established standards ensures that all new accounts meet a defined baseline of security and configuration.

Concept tested: Security policies, standards, and guidelines

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf

Topics

#Security documentation#Standards#User account provisioning#Information security program management

Community Discussion

No community discussion yet for this question.

Full CISM Practice