CISM · Question #586
Which of the following is MOST likely to require an organization to update its information security program?
The correct answer is A. A new confidentiality requirement. Option A is correct because a new confidentiality requirement - whether from regulation, law, or contract - creates a formal obligation that the security program must reflect. Information security programs are policy-driven frameworks, and when the rules governing data protection
Question
Which of the following is MOST likely to require an organization to update its information security program?
Options
- AA new confidentiality requirement
- BA zero-day vulnerability
- CA poor key performance indicator (KPI)
- DA new industry benchmarking analysis
How the community answered
(35 responses)- A83% (29)
- B9% (3)
- C3% (1)
- D6% (2)
Explanation
Option A is correct because a new confidentiality requirement - whether from regulation, law, or contract - creates a formal obligation that the security program must reflect. Information security programs are policy-driven frameworks, and when the rules governing data protection change, the program must be updated to remain compliant and enforceable.
Why the distractors are wrong:
- B (Zero-day vulnerability): This triggers an operational/tactical response (patching, workarounds, monitoring) handled within existing incident response processes - not a program-level rewrite.
- C (Poor KPI): A bad metric signals underperformance within the current program, which might drive process improvement, but doesn't require changing the program itself.
- D (Industry benchmarking): Benchmarking is advisory and informational. It may inform future decisions, but it creates no obligation to update the program.
Memory tip: Think "Requirements drive rewrites." Regulatory, legal, or contractual changes are the clearest trigger for updating a security program because they shift what the organization is obligated to do - not just what it should consider doing.
Topics
Community Discussion
No community discussion yet for this question.