nerdexam
Isaca

CISM · Question #475

Which of the following should an information security manager do FIRST when new regulation requires a significant investment to upgrade a legacy application?

The correct answer is B. Assess the business impact to the organization. The first step when facing a new regulation that requires a significant investment in upgrading a legacy application is to assess the business impact. This helps determine how noncompliance affects operations, financials, and regulatory standing, allowing for informed…

Submitted by thandi_sa· Apr 18, 2026Information Security Governance

Question

Which of the following should an information security manager do FIRST when new regulation requires a significant investment to upgrade a legacy application?

Options

  • ADevelop an implementation roadmap.
  • BAssess the business impact to the organization.
  • CDetermine compensating controls to reduce the risk.
  • DDetermine the cost to remediate the noncompliance.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    76% (19)
  • C
    12% (3)
  • D
    4% (1)

Explanation

The first step when facing a new regulation that requires a significant investment in upgrading a legacy application is to assess the business impact. This helps determine how noncompliance affects operations, financials, and regulatory standing, allowing for informed decision-making. Once the impact is understood, the organization can develop an implementation roadmap, explore compensating controls, or evaluate remediation costs.

Topics

#Regulatory Compliance#Business Impact Analysis#Information Security Governance#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice