Isaca
CISM · Question #884
Which of the following would be an information security manager's BEST course of action when a new cybersecurity regulation is published?
The correct answer is C. Conduct a security risk assessment. The best course of action is to conduct a security risk assessment to understand how the new regulation affects the organization’s risk exposure and obligations, which then drives appropriate updates to strategy, plans, and metrics.
Submitted by diego_uy· Apr 18, 2026Information Security Risk Management
Question
Which of the following would be an information security manager's BEST course of action when a new cybersecurity regulation is published?
Options
- AUpdate the security strategy.
- BReview the security operational project plan.
- CConduct a security risk assessment.
- DAdjust the security metrics dashboard.
How the community answered
(35 responses)- A6% (2)
- B14% (5)
- C77% (27)
- D3% (1)
Explanation
The best course of action is to conduct a security risk assessment to understand how the new regulation affects the organization’s risk exposure and obligations, which then drives appropriate updates to strategy, plans, and metrics.
Topics
#Cybersecurity Regulation#Risk Assessment#Compliance#Security Management
Community Discussion
No community discussion yet for this question.