CISM · Question #625
An organization is planning to open a new office in another country. Sensitive data will be routinely sent between the two offices. What should be the information security manager's FIRST course of…
The correct answer is C. Identify applicable regulatory requirements to establish security policies. Why C is correct: Before any policies, training, or technical controls can be designed, the security manager must first understand what rules apply - identifying the regulatory requirements of the new country establishes the legal and compliance baseline that everything else is…
Question
An organization is planning to open a new office in another country. Sensitive data will be routinely sent between the two offices. What should be the information security manager’s FIRST course of action?
Options
- AUpdate privacy policies to include the other country's laws and regulations.
- BDevelop customized security training for employees at the new office.
- CIdentify applicable regulatory requirements to establish security policies.
- DEncrypt the data for transfer to the head office based on security manager approval.
How the community answered
(39 responses)- A3% (1)
- B15% (6)
- C72% (28)
- D10% (4)
Explanation
Why C is correct: Before any policies, training, or technical controls can be designed, the security manager must first understand what rules apply - identifying the regulatory requirements of the new country establishes the legal and compliance baseline that everything else is built upon. You cannot write valid policies or choose appropriate controls without knowing what you're obligated to comply with.
Why the distractors fail:
- A is a downstream task - you update privacy policies after you know which laws apply, not before.
- B is also premature - training content must reflect established policies, which first require regulatory grounding.
- D jumps straight to a technical control and assumes encryption is the right solution, skipping the foundational analysis that would confirm or refute that assumption.
Memory tip: Think of security management as building a house - regulations are the zoning laws (C). You must check zoning before drawing blueprints (A), hiring workers (B), or ordering materials (D). "First" questions on security exams almost always point to the governance/compliance layer, not the technical layer.
Topics
Community Discussion
No community discussion yet for this question.