Certified Information Security Manager CISM · Free Practice Question Easy
Question 69
-
A
Publish security policies on the organization’s intranet.
-
B
Publish security policies on the public Internet.
-
C
Perform an organization-wide risk assessment.
-
D
Examine the organization’s practices to see whether they align with policies.
Reveal correct answer
Correct answer: D
Explanation
Correct Answer:
"Examine the organization’s practices to see whether they align with policies." is correct. It is not advisable simply to publish these security policies before understanding the organization’s level of compliance with them. It’s better for the security manager to start by examining the organization’s practices and determining how well they align with policy.
Incorrect Answers:
"Publish security policies on the organization’s intranet." is incorrect because there may be a valid reason why policies are unpublished, and this should be first determined.
"Publish security policies on the public Internet." is incorrect because organizations rarely publish their security policies to the public.
"Perform an organization-wide risk assessment." is incorrect because a risk assessment will not contribute meaningfully to this problem.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
