nerdexam
Isaca

CISM · Question #651

An organization is in the process of defining policies for employee use of social media. It is MOST important for the information security manager to:

The correct answer is B. evaluate risks to the organization. Policy development must be grounded in a thorough risk assessment. Before selecting monitoring tools, assigning accountability, or creating training, the information security manager must first understand what risks social media use poses to the organization (e.g., data…

Submitted by olafpl· Apr 18, 2026Information Security Risk Management

Question

An organization is in the process of defining policies for employee use of social media. It is MOST important for the information security manager to:

Options

  • Aidentify security monitoring tools.
  • Bevaluate risks to the organization.
  • Cassign accountability for monitoring social media.
  • Ddevelop security awareness training.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    80% (28)
  • C
    11% (4)
  • D
    6% (2)

Explanation

Policy development must be grounded in a thorough risk assessment. Before selecting monitoring tools, assigning accountability, or creating training, the information security manager must first understand what risks social media use poses to the organization (e.g., data leakage, reputational harm, phishing vectors). Risk evaluation drives the scope, content, and controls within the policy. All other options are downstream activities that depend on understanding the risk landscape first.

Topics

#Risk evaluation#Policy development#Social media security#Information security planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice