Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 3 Question 111 Discussion

An information security manager learns of a new standard related to an emerging technology the organization wants to implement. Which of the following should the information security manager recommend be done FIRST?
A) Determine whether the organization can benefit from adopting the new standard.
B) Obtain legal counsel's opinion on the standard's applicability to regulations,
C) Perform a risk assessment on the new technology.
D) Review industry specialists' analyses of the new standard.

Isaca CISM Exam - Topic 3 Question 111 Discussion

Actual exam question for Isaca's CISM exam
Question #: 111
Topic #: 3
[All CISM Questions]

An information security manager learns of a new standard related to an emerging technology the organization wants to implement. Which of the following should the information security manager recommend be done FIRST?

Show Suggested Answer Hide Answer
Suggested Answer: A

= The first step that the information security manager should recommend when learning of a new standard related to an emerging technology is to determine whether the organization can benefit from adopting the new standard. This involves evaluating the business objectives, needs, and requirements of the organization, as well as the potential advantages, disadvantages, and challenges of implementing the new technology and the new standard. The information security manager should also consider the alignment of the new standard with the organization's existing policies, procedures, and standards, as well as the impact of the new standard on the organization's information security governance, risk management, program, and incident management. By conducting a preliminary analysis of the feasibility, suitability, and desirability of the new standard, the information security manager can provide a sound basis for further decision making and planning.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Standards, page 391; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 43, page 412.


Contribute your Thoughts:

0/2000 characters
Margot
10 hours ago
C) makes sense, but it feels like a lot of work upfront.
upvoted 0 times
...
Marcelle
6 days ago
I disagree, B) should come first to avoid legal issues.
upvoted 0 times
...
Royce
11 days ago
A) is definitely the first step!
upvoted 0 times
...
Alecia
16 days ago
Reviewing industry specialists' analyses sounds important too, but I think we need to prioritize understanding the potential benefits first.
upvoted 0 times
...
Vince
2 months ago
I feel like performing a risk assessment on the new technology is crucial, but I wonder if we should first understand the standard itself.
upvoted 0 times
...
Von
2 months ago
I'm not entirely sure, but I remember a practice question that emphasized the importance of legal counsel. Maybe option B is the right choice?
upvoted 0 times
...
Keith
2 months ago
I think the first step should be to determine if the organization can benefit from the new standard. It makes sense to know if it's worth pursuing.
upvoted 0 times
...

Save Cancel