Certified Information Security Manager CISM · Free Practice Question Medium

Question 56

A security manager is developing a long-term security strategy and examines a security policy on the topic of access management that was last reviewed five years ago. What conclusion can the security manager draw from this?
  • A The organization’s access management practices have not needed to be changed in many years.
  • B

    The organization has neglected to conduct a periodic review of its policy documents.

  • C Access management is not a high-risk activity in the organization.
  • D The policy is so durable that it has not needed to be changed.
Reveal correct answer

Correct answer: B

Explanation

Correct Answer:

"The organization has neglected to conduct a periodic review of its policy documents." is correct. Policies should be reviewed, and updated if necessary, at least once each year.

Incorrect Answers:

The remaining answers are incorrect. Although an organization’s policy may be durable, policies should be reviewed annually, regardless of risk.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need