nerdexam
Isaca

CISM · Question #895

Which of the following should an information security manager do FIRST when there is a conflict between the organization's information security policy and a local regulation?

The correct answer is C. Obtain legal guidance. When a conflict exists between an internal policy and an external legal regulation, the information security manager must first obtain legal guidance before taking any action. Legal counsel can clarify the applicability of the regulation, any exemptions, and the legal risk of…

Submitted by tom_us· Apr 18, 2026Information Security Governance

Question

Which of the following should an information security manager do FIRST when there is a conflict between the organization's information security policy and a local regulation?

Options

  • AEnforce the local regulation.
  • BObtain an independent assessment of the regulation.
  • CObtain legal guidance.
  • DEnforce the organization's information security policy.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    13% (4)
  • C
    77% (23)
  • D
    7% (2)

Explanation

When a conflict exists between an internal policy and an external legal regulation, the information security manager must first obtain legal guidance before taking any action. Legal counsel can clarify the applicability of the regulation, any exemptions, and the legal risk of non-compliance. Enforcing the regulation (A) or the internal policy (D) without legal advice could expose the organization to liability. An independent assessment (B) may follow legal guidance but is not the first step. Acting without legal clarity in a regulatory conflict is a serious governance and compliance risk.

Topics

#Regulatory compliance#Policy conflict#Legal guidance#Information security governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice