CISM · Question #654
Which of the following is the MOST important reason for an information security manager to understand legal and regulatory compliance requirements?
The correct answer is C. Compliance requirements may impose constraints on security strategy. Legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS) can mandate specific controls, restrict data handling practices, or require certain configurations - directly constraining how the security strategy can be designed and implemented. Understanding these requirements…
Question
Which of the following is the MOST important reason for an information security manager to understand legal and regulatory compliance requirements?
Options
- AThe compliance department may not understand IT-related compliance issues
- BGlobal information security standards require compliance requirements to be considered
- CCompliance requirements may impose constraints on security strategy
- DThe risk of financial penalties associated with noncompliance is higher than other types of risk
How the community answered
(33 responses)- A3% (1)
- B6% (2)
- C79% (26)
- D12% (4)
Explanation
Legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS) can mandate specific controls, restrict data handling practices, or require certain configurations - directly constraining how the security strategy can be designed and implemented. Understanding these requirements enables the security manager to build a strategy that is both effective and legally compliant. The other options reflect valid but secondary concerns: the compliance team may need IT input (A), standards reference compliance (B), and financial penalties are one type of risk among many (D).
Topics
Community Discussion
No community discussion yet for this question.