nerdexam
Isaca

CISM · Question #987

Which of the following would cause the GREATEST concern to a newly hired information security manager reviewing an organization's risk management program?

The correct answer is D. Security procedures contain both mandatory and discretionary actions. Security procedures are meant to be prescriptive - they define exactly how controls must be implemented to ensure consistent, auditable security outcomes. Procedures that mix mandatory and discretionary actions undermine this purpose: discretionary steps create inconsistency…

Submitted by jaden.t· Apr 18, 2026Information Security Risk Management

Question

Which of the following would cause the GREATEST concern to a newly hired information security manager reviewing an organization's risk management program?

Options

  • ASecurity standards are owned by operations.
  • BSecurity policies are linked to key risk indicators (KRIs).
  • CSecurity standards are reviewed only once a year.
  • DSecurity procedures contain both mandatory and discretionary actions.

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    19% (5)
  • D
    67% (18)

Explanation

Security procedures are meant to be prescriptive - they define exactly how controls must be implemented to ensure consistent, auditable security outcomes. Procedures that mix mandatory and discretionary actions undermine this purpose: discretionary steps create inconsistency, make compliance audits unreliable, and introduce gaps that can be exploited. This is a fundamental governance deficiency. By contrast, standards owned by operations (A) is unconventional but not inherently dangerous, policies linked to KRIs (B) is actually good practice, and annual standards reviews (C) are common and generally acceptable.

Topics

#Risk Management Program#Security Procedures#Security Controls#Risk Mitigation Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice