CISM · Question #885
A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What should be done FIRST?
The correct answer is A. Inventory and review current security policies.. The first step is to inventory and review the existing security policies and procedures to understand what currently exists, identify outdated or missing items, and establish the baseline needed before assessing regulatory changes, aligning to best practices, or performing deeper
Question
A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What should be done FIRST?
Options
- AInventory and review current security policies.
- BReview legal and regulatory requirements.
- CUpdate in accordance with the best business practices.
- DPerform a risk assessment of the current IT environment.
How the community answered
(29 responses)- A83% (24)
- C10% (3)
- D7% (2)
Explanation
The first step is to inventory and review the existing security policies and procedures to understand what currently exists, identify outdated or missing items, and establish the baseline needed before assessing regulatory changes, aligning to best practices, or performing deeper risk-based updates.
Topics
Community Discussion
No community discussion yet for this question.