CISM · Question #943
Which of the following is the MOST important reason for an organization's information security manager to actively engage with the compliance department?
The correct answer is D. To gain an understanding of changes in various legal and regulatory compliance requirements. Actively engaging with the compliance department gives the information security manager early visibility into changes in legal and regulatory requirements - this is the most important reason because it allows security programs to be proactively adapted before noncompliance…
Question
Which of the following is the MOST important reason for an organization's information security manager to actively engage with the compliance department?
Options
- ATo explain technical issues related to noncompliance
- BTo provide compliance reporting related to IT and security
- CTo collaborate with the compliance department on the application of compliance requirements
- DTo gain an understanding of changes in various legal and regulatory compliance requirements
How the community answered
(50 responses)- A6% (3)
- B10% (5)
- C28% (14)
- D56% (28)
Explanation
Actively engaging with the compliance department gives the information security manager early visibility into changes in legal and regulatory requirements - this is the most important reason because it allows security programs to be proactively adapted before noncompliance occurs, rather than reacting after the fact.
Why the distractors fall short:
- A (explaining technical issues) is a one-way, reactive activity - it's something the security manager does for compliance, not a primary reason to engage with them.
- B (providing compliance reporting) is also a deliverable the security manager provides, not a strategic reason to engage; reports can be sent without active collaboration.
- C (collaborating on applying requirements) is valuable but secondary - you can only collaborate effectively once you first understand what the requirements are, making D the prerequisite.
Memory tip: Think of the security manager as someone who must anticipate, not just react. The most important reason to engage with compliance is always about gaining knowledge first (D) - without knowing what's changing in the regulatory landscape, none of the other activities (explaining, reporting, collaborating) can be done effectively.
Topics
Community Discussion
No community discussion yet for this question.