Isaca
CISM · Question #788
A new information security reporting requirement will soon become effective. Which of the following should be the information security manager's FIRST action?
Sign in or unlock CISM to reveal the answer and full explanation for question #788. The question stem and answer options stay visible for context.
Submitted by brentm· Apr 18, 2026Information Security Governance
Question
A new information security reporting requirement will soon become effective. Which of the following should be the information security manager's FIRST action?
Options
- AConduct a cost-benefit analysis related to noncompliance with the new requirement.
- BPerform a gap assessment against the new requirement.
- CInvestigate to determine whether the new requirement applies to the business.
- DInform senior management of the new requirement.
Unlock CISM to see the answer
You've previewed enough free CISM questions. Unlock CISM for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Regulatory compliance#Legal & regulatory requirements#Information security governance#Compliance management