nerdexam
Isaca

CISM · Question #973

A senior executive asks the information security manager to bypass the organization's internet traffic filters due to a business need. Which of the following should be the information security…

The correct answer is D. Follow the controls exception process. The appropriate next step is to follow the established controls exception process so the request is formally risk-assessed, documented, approved by the proper authority, time-bound, and monitored rather than handled ad hoc.

Submitted by lars.no· Apr 18, 2026Information Security Governance

Question

A senior executive asks the information security manager to bypass the organization's internet traffic filters due to a business need. Which of the following should be the information security manager's NEXT course of action?

Options

  • ADeny the request as noncompliant with policy.
  • BImplement the exception request.
  • CNotify the IT network manager and make an approval decision jointly.
  • DFollow the controls exception process.

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    7% (1)
  • C
    7% (1)
  • D
    79% (11)

Explanation

The appropriate next step is to follow the established controls exception process so the request is formally risk-assessed, documented, approved by the proper authority, time-bound, and monitored rather than handled ad hoc.

Topics

#Controls exception process#Security governance#Policy compliance#Risk management

Community Discussion

No community discussion yet for this question.

Full CISM Practice