nerdexam
Isaca

CISM · Question #884

Which of the following would be an information security manager's BEST course of action when a new cybersecurity regulation is published?

The correct answer is C. Conduct a security risk assessment. The best course of action is to conduct a security risk assessment to understand how the new regulation affects the organization’s risk exposure and obligations, which then drives appropriate updates to strategy, plans, and metrics.

Submitted by diego_uy· Apr 18, 2026Information Security Risk Management

Question

Which of the following would be an information security manager's BEST course of action when a new cybersecurity regulation is published?

Options

  • AUpdate the security strategy.
  • BReview the security operational project plan.
  • CConduct a security risk assessment.
  • DAdjust the security metrics dashboard.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    77% (27)
  • D
    3% (1)

Explanation

The best course of action is to conduct a security risk assessment to understand how the new regulation affects the organization’s risk exposure and obligations, which then drives appropriate updates to strategy, plans, and metrics.

Topics

#Cybersecurity Regulation#Risk Assessment#Compliance#Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice