Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 4 Question 116 Discussion

Which of the following should be done FIRST to determine the impact of a new regulatory requirement for cloud services?
C) Determine the applicability
A) Perform a risk assessment
B) Review the information asset inventory
D) Conduct a gap analysis

Isaca CISM Exam - Topic 4 Question 116 Discussion

Actual exam question for Isaca's CISM exam
Question #: 116
Topic #: 4
[All CISM Questions]

Which of the following should be done FIRST to determine the impact of a new regulatory requirement for cloud services?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C because before assessing impact, performing a gap analysis, or conducting a risk assessment, the organization must first determine whether the new regulatory requirement applies to its cloud services, data, jurisdictions, customers, industry, and processing activities. Applicability establishes whether the regulation is relevant and which systems, processes, contracts, business units, or data types are in scope. A risk assessment is important after applicability is confirmed, but performing it too early may waste resources or miss the correct scope. Reviewing the asset inventory may support scoping, but it should follow or support the applicability analysis. A gap analysis compares current practices against requirements, but this cannot be done properly until the organization confirms that the requirement applies and understands its scope. CISM risk management emphasizes identifying legal, regulatory, and contractual obligations as part of risk and compliance management. Therefore, determining applicability is the first step in understanding the impact of a new regulatory requirement.


Contribute your Thoughts:

0/2000 characters
Lilli
1 day ago
Surprised that people think risk assessment is the first move!
upvoted 0 times
...
Ettie
6 days ago
Gap analysis seems too late in the process.
upvoted 0 times
...
Vilma
11 days ago
Wait, shouldn't we determine applicability first?
upvoted 0 times
...
German
17 days ago
I think reviewing the asset inventory should come first.
upvoted 0 times
...
Ena
22 days ago
A risk assessment is definitely the first step!
upvoted 0 times
...
Gregg
27 days ago
I thought gap analysis was key, but now I'm wondering if we need to check the applicability first. This is tricky!
upvoted 0 times
...
Odette
1 month ago
I practiced a question like this, and I feel like performing a risk assessment is crucial, but I can't recall if it should be the very first thing.
upvoted 0 times
...
Donte
1 month ago
I'm not entirely sure, but I remember something about reviewing the information asset inventory being important. Maybe that should come first?
upvoted 0 times
...
Tatum
1 month ago
I think the first step should be to determine the applicability. It makes sense to know if the regulation even applies to us before doing anything else.
upvoted 0 times
...

Save Cancel