nerdexam
Isaca

CISM · Question #481

An information security manager finds that the security function is reactive instead of proactive when responding to changing business processes. Which of the following is the BEST way to address…

The correct answer is B. Implement a policy requiring information security involvement with change management. To shift from a reactive to a proactive security approach, it is essential to embed security within the change management process. A policy requiring information security involvement in business changes ensures that security considerations are addressed early in the process…

Submitted by joshua94· Apr 18, 2026Information Security Governance

Question

An information security manager finds that the security function is reactive instead of proactive when responding to changing business processes. Which of the following is the BEST way to address this situation?

Options

  • AHighlight the concerns to the CEO with a summary of business impact.
  • BImplement a policy requiring information security involvement with change management.
  • CProvide information security user awareness training (UAT) to the business.
  • DEstablish regular communication with other business unit managers.

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    72% (26)
  • C
    6% (2)
  • D
    8% (3)

Explanation

To shift from a reactive to a proactive security approach, it is essential to embed security within the change management process. A policy requiring information security involvement in business changes ensures that security considerations are addressed early in the process, rather than after changes are implemented. While executive support, user awareness, and business communication are beneficial, formal integration into change management is the most effective

Topics

#Proactive Security#Change Management Integration#Security Policy#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice