Isaca
CISM · Question #873
Which of the following should an information security manager do FIRST after a new cybersecurity regulation has been introduced?
The correct answer is A. Perform a gap analysis.. A new regulation introduces business, legal, and strategic implications. Senior management must be informed first to set direction, determine urgency, and allocate resources.
Submitted by ravi_2018· Apr 18, 2026Information Security Governance
Question
Which of the following should an information security manager do FIRST after a new cybersecurity regulation has been introduced?
Options
- APerform a gap analysis.
- BUpdate the risk register.
- CInform senior management.
- DConduct a cost-benefit analysis.
How the community answered
(20 responses)- A85% (17)
- B5% (1)
- D10% (2)
Explanation
A new regulation introduces business, legal, and strategic implications. Senior management must be informed first to set direction, determine urgency, and allocate resources.
Topics
#Regulatory Compliance#Gap Analysis#Information Security Governance#Compliance Management
Community Discussion
No community discussion yet for this question.