nerdexam
Isaca

CISM · Question #591

An information security manager has become aware that system administrators are not changing server administrator accounts from the default usernames. A policy has been created and approved by…

The correct answer is A. Ensure the policy has been communicated to the system administrators. The first step is to confirm that system administrators are aware of the new policy. Without proper communication, they may not know the requirement exists, making enforcement and compliance

Submitted by ricky.ec· Apr 18, 2026Information Security Program Development and Management

Question

An information security manager has become aware that system administrators are not changing server administrator accounts from the default usernames. A policy has been created and approved by business managers to require these changes. Which of the following should be the information security manager's FIRST course of action?

Options

  • AEnsure the policy has been communicated to the system administrators.
  • BInclude the requirement in information security awareness materials.
  • CPerform a policy compliance assessment.
  • DRequire system administrators to sign off on the policy.

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    7% (2)
  • C
    18% (5)
  • D
    4% (1)

Explanation

The first step is to confirm that system administrators are aware of the new policy. Without proper communication, they may not know the requirement exists, making enforcement and compliance

Topics

#Policy Communication#Policy Implementation#Information Security Policy

Community Discussion

No community discussion yet for this question.

Full CISM Practice