nerdexam
Isaca

CISM · Question #579

The department head of application development has decided to accept the risks identified in a recent assessment. No recommendations will be implemented, even though the recommendations are required…

The correct answer is A. Advise the risk management team. When regulatory requirements are involved and the risk is being accepted inappropriately, the information security manager must escalate the issue by advising the risk management team to ensure compliance and prevent organizational exposure to legal or regulatory penalties.

Submitted by weili_xi· Apr 18, 2026Information Security Risk Management

Question

The department head of application development has decided to accept the risks identified in a recent assessment. No recommendations will be implemented, even though the recommendations are required by regulatory oversight. What should the information security manager do NEXT?

Options

  • AAdvise the risk management team.
  • BFormally document the decision.
  • CReview the regulations.
  • DReview the risk monitoring plan.

How the community answered

(31 responses)
  • A
    81% (25)
  • B
    6% (2)
  • C
    10% (3)
  • D
    3% (1)

Explanation

When regulatory requirements are involved and the risk is being accepted inappropriately, the information security manager must escalate the issue by advising the risk management team to ensure compliance and prevent organizational exposure to legal or regulatory penalties.

Topics

#risk acceptance#regulatory non-compliance#escalation#ISM responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice