nerdexam
Isaca

CISM · Question #586

Which of the following is MOST likely to require an organization to update its information security program?

The correct answer is A. A new confidentiality requirement. Option A is correct because a new confidentiality requirement - whether from regulation, law, or contract - creates a formal obligation that the security program must reflect. Information security programs are policy-driven frameworks, and when the rules governing data protection

Submitted by lars.no· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST likely to require an organization to update its information security program?

Options

  • AA new confidentiality requirement
  • BA zero-day vulnerability
  • CA poor key performance indicator (KPI)
  • DA new industry benchmarking analysis

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    9% (3)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Option A is correct because a new confidentiality requirement - whether from regulation, law, or contract - creates a formal obligation that the security program must reflect. Information security programs are policy-driven frameworks, and when the rules governing data protection change, the program must be updated to remain compliant and enforceable.

Why the distractors are wrong:

  • B (Zero-day vulnerability): This triggers an operational/tactical response (patching, workarounds, monitoring) handled within existing incident response processes - not a program-level rewrite.
  • C (Poor KPI): A bad metric signals underperformance within the current program, which might drive process improvement, but doesn't require changing the program itself.
  • D (Industry benchmarking): Benchmarking is advisory and informational. It may inform future decisions, but it creates no obligation to update the program.

Memory tip: Think "Requirements drive rewrites." Regulatory, legal, or contractual changes are the clearest trigger for updating a security program because they shift what the organization is obligated to do - not just what it should consider doing.

Topics

#Information Security Program#Program Management#Compliance#Regulatory Requirements

Community Discussion

No community discussion yet for this question.

Full CISM Practice