Certified Information Security Manager CISM · Free Practice Question Medium
Question 56
A security manager is developing a long-term security strategy and examines a security policy on the topic of access management that was last reviewed five years ago. What conclusion can the security manager draw from this?
- A The organization’s access management practices have not needed to be changed in many years.
-
B
The organization has neglected to conduct a periodic review of its policy documents.
- C Access management is not a high-risk activity in the organization.
- D The policy is so durable that it has not needed to be changed.
Reveal correct answer
Correct answer: B
Explanation
Correct Answer:
"The organization has neglected to conduct a periodic review of its policy documents." is correct. Policies should be reviewed, and updated if necessary, at least once each year.
Incorrect Answers:
The remaining answers are incorrect. Although an organization’s policy may be durable, policies should be reviewed annually, regardless of risk.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
