CISM · Question #783
What should be an information security manager's FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?
The correct answer is B. Assess the risk of noncompliance. Assessing the risk of noncompliance ensures that decisions are based on an understanding of the business impact and security implications. "Before reporting or remediating, it is critical to assess the risk associated with the control bypass to make informed decisions."
Question
What should be an information security manager's FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?
Options
- AReport the noncompliance to senior management.
- BAssess the risk of noncompliance.
- CActivate the incident response plan.
- DEvaluate possible compensating controls.
How the community answered
(50 responses)- A8% (4)
- B78% (39)
- C12% (6)
- D2% (1)
Explanation
Assessing the risk of noncompliance ensures that decisions are based on an understanding of the business impact and security implications. "Before reporting or remediating, it is critical to assess the risk associated with the control bypass to make informed decisions."
Topics
Community Discussion
No community discussion yet for this question.