Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 3 Question 111 Discussion

Actual exam question for Isaca's CISM exam
Question #: 111
Topic #: 3
[All CISM Questions]

An information security manager learns of a new standard related to an emerging technology the organization wants to implement. Which of the following should the information security manager recommend be done FIRST?

Show Suggested Answer Hide Answer
Suggested Answer: A

= The first step that the information security manager should recommend when learning of a new standard related to an emerging technology is to determine whether the organization can benefit from adopting the new standard. This involves evaluating the business objectives, needs, and requirements of the organization, as well as the potential advantages, disadvantages, and challenges of implementing the new technology and the new standard. The information security manager should also consider the alignment of the new standard with the organization's existing policies, procedures, and standards, as well as the impact of the new standard on the organization's information security governance, risk management, program, and incident management. By conducting a preliminary analysis of the feasibility, suitability, and desirability of the new standard, the information security manager can provide a sound basis for further decision making and planning.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Standards, page 391; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 43, page 412.


Contribute your Thoughts:

0/2000 characters
Vince
17 days ago
I feel like performing a risk assessment on the new technology is crucial, but I wonder if we should first understand the standard itself.
upvoted 0 times
...
Von
22 days ago
I'm not entirely sure, but I remember a practice question that emphasized the importance of legal counsel. Maybe option B is the right choice?
upvoted 0 times
...
Keith
27 days ago
I think the first step should be to determine if the organization can benefit from the new standard. It makes sense to know if it's worth pursuing.
upvoted 0 times
...

Save Cancel