nerdexam
Isaca

CISM · Question #411

A business unit has designed a mobile app to provide services to customers. Which of the following is an information security manager's BEST approach when the business resists implementing a strong pa

The correct answer is A. Review the security risk with the business unit.. The best approach is to collaborate with the business unit by reviewing the security risks associated with weak passwords. This allows the security manager to communicate the potential threats in a way that aligns with business objectives. By discussing possible alternatives, suc

Submitted by katya_ua· Apr 18, 2026Information Security Risk Management

Question

A business unit has designed a mobile app to provide services to customers. Which of the following is an information security manager's BEST approach when the business resists implementing a strong password policy due to concerns about the user experience?

Options

  • AReview the security risk with the business unit.
  • BEvaluate the costs and benefits of improving the user experience.
  • CPresent the risk and user impact to senior management.
  • DRequire the business unit to adhere to the policy.

How the community answered

(26 responses)
  • A
    46% (12)
  • B
    8% (2)
  • C
    15% (4)
  • D
    31% (8)

Explanation

The best approach is to collaborate with the business unit by reviewing the security risks associated with weak passwords. This allows the security manager to communicate the potential threats in a way that aligns with business objectives. By discussing possible alternatives, such as multi-factor authentication (MFA) or biometric authentication, the security manager can help find a balance between security and user experience without imposing rigid policies.

Topics

#Risk Communication#Stakeholder Management#Password Policies#Security vs. Usability

Community Discussion

No community discussion yet for this question.

Full CISM Practice