nerdexam
Isaca

CISM · Question #654

Which of the following is the MOST important reason for an information security manager to understand legal and regulatory compliance requirements?

The correct answer is C. Compliance requirements may impose constraints on security strategy. Legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS) can mandate specific controls, restrict data handling practices, or require certain configurations - directly constraining how the security strategy can be designed and implemented. Understanding these requirements…

Submitted by sofia.br· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST important reason for an information security manager to understand legal and regulatory compliance requirements?

Options

  • AThe compliance department may not understand IT-related compliance issues
  • BGlobal information security standards require compliance requirements to be considered
  • CCompliance requirements may impose constraints on security strategy
  • DThe risk of financial penalties associated with noncompliance is higher than other types of risk

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    79% (26)
  • D
    12% (4)

Explanation

Legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS) can mandate specific controls, restrict data handling practices, or require certain configurations - directly constraining how the security strategy can be designed and implemented. Understanding these requirements enables the security manager to build a strategy that is both effective and legally compliant. The other options reflect valid but secondary concerns: the compliance team may need IT input (A), standards reference compliance (B), and financial penalties are one type of risk among many (D).

Topics

#Legal & Regulatory Compliance#Security Strategy#Information Security Governance#Compliance Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice