CISM · Question #973
A senior executive asks the information security manager to bypass the organization's internet traffic filters due to a business need. Which of the following should be the information security…
The correct answer is D. Follow the controls exception process. The appropriate next step is to follow the established controls exception process so the request is formally risk-assessed, documented, approved by the proper authority, time-bound, and monitored rather than handled ad hoc.
Question
A senior executive asks the information security manager to bypass the organization's internet traffic filters due to a business need. Which of the following should be the information security manager's NEXT course of action?
Options
- ADeny the request as noncompliant with policy.
- BImplement the exception request.
- CNotify the IT network manager and make an approval decision jointly.
- DFollow the controls exception process.
How the community answered
(14 responses)- A7% (1)
- B7% (1)
- C7% (1)
- D79% (11)
Explanation
The appropriate next step is to follow the established controls exception process so the request is formally risk-assessed, documented, approved by the proper authority, time-bound, and monitored rather than handled ad hoc.
Topics
Community Discussion
No community discussion yet for this question.