nerdexam
Isaca

CISM · Question #873

Which of the following should an information security manager do FIRST after a new cybersecurity regulation has been introduced?

The correct answer is A. Perform a gap analysis.. A new regulation introduces business, legal, and strategic implications. Senior management must be informed first to set direction, determine urgency, and allocate resources.

Submitted by ravi_2018· Apr 18, 2026Information Security Governance

Question

Which of the following should an information security manager do FIRST after a new cybersecurity regulation has been introduced?

Options

  • APerform a gap analysis.
  • BUpdate the risk register.
  • CInform senior management.
  • DConduct a cost-benefit analysis.

How the community answered

(20 responses)
  • A
    85% (17)
  • B
    5% (1)
  • D
    10% (2)

Explanation

A new regulation introduces business, legal, and strategic implications. Senior management must be informed first to set direction, determine urgency, and allocate resources.

Topics

#Regulatory Compliance#Gap Analysis#Information Security Governance#Compliance Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice