nerdexam
Isaca

CISM · Question #783

What should be an information security manager's FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?

The correct answer is B. Assess the risk of noncompliance. Assessing the risk of noncompliance ensures that decisions are based on an understanding of the business impact and security implications. "Before reporting or remediating, it is critical to assess the risk associated with the control bypass to make informed decisions."

Submitted by wei.xz· Apr 18, 2026Information Security Risk Management

Question

What should be an information security manager's FIRST course of action upon learning a business unit is bypassing an existing control in order to increase operational efficiency?

Options

  • AReport the noncompliance to senior management.
  • BAssess the risk of noncompliance.
  • CActivate the incident response plan.
  • DEvaluate possible compensating controls.

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    78% (39)
  • C
    12% (6)
  • D
    2% (1)

Explanation

Assessing the risk of noncompliance ensures that decisions are based on an understanding of the business impact and security implications. "Before reporting or remediating, it is critical to assess the risk associated with the control bypass to make informed decisions."

Topics

#Risk assessment#Control bypass#Noncompliance#Information security management

Community Discussion

No community discussion yet for this question.

Full CISM Practice