nerdexam
Isaca

CISM · Question #819

Which of the following is the BEST approach for reporting information security noncompliance to senior management?

The correct answer is D. Explain the potential impact of noncompliance.. Senior management is primarily concerned with business impact. Explaining the potential impact of noncompliance translates security issues into business risk, enabling informed decision- making, whereas root causes or remediation costs are secondary at the executive level.

Submitted by joshua94· Apr 18, 2026Information Security Governance

Question

Which of the following is the BEST approach for reporting information security noncompliance to senior management?

Options

  • AExplain the root cause of the noncompliance.
  • BExplain the cost of remediation for noncompliance.
  • CExplain scenarios of noncompliance at competing organizations.
  • DExplain the potential impact of noncompliance.

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    10% (5)
  • D
    82% (42)

Explanation

Senior management is primarily concerned with business impact. Explaining the potential impact of noncompliance translates security issues into business risk, enabling informed decision- making, whereas root causes or remediation costs are secondary at the executive level.

Topics

#Reporting to management#Noncompliance reporting#Risk impact#Information security governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice