Certified Information Security Manager CISM · Free Practice Question Easy

Question 69

A new security manager has discovered that the security policy is not published. What is the best course of action?
  • A

    Publish security policies on the organization’s intranet.

  • B

    Publish security policies on the public Internet.

  • C

    Perform an organization-wide risk assessment.

  • D

    Examine the organization’s practices to see whether they align with policies.

Reveal correct answer

Correct answer: D

Explanation

Correct Answer:

"Examine the organization’s practices to see whether they align with policies." is correct. It is not advisable simply to publish these security policies before understanding the organization’s level of compliance with them. It’s better for the security manager to start by examining the organization’s practices and determining how well they align with policy.

Incorrect Answers:

"Publish security policies on the organization’s intranet." is incorrect because there may be a valid reason why policies are unpublished, and this should be first determined.

"Publish security policies on the public Internet." is incorrect because organizations rarely publish their security policies to the public.

"Perform an organization-wide risk assessment." is incorrect because a risk assessment will not contribute meaningfully to this problem.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need