QuestionQ621

Information Security Program

An information security manager discovers that IT personnel are not complying with the information security policy because it causes process inefficiencies. What should the information security manager do FIRST?

  • A Propose that IT update information security policies and procedures.
  • B Request that internal audit conduct a review of the policy development process.
  • C Conduct user awareness training within the IT function.
  • D Determine the risk related to noncompliance with the policy.
Explanation

The risk arising from policy noncompliance must be assessed first so that the security manager can understand its potential impact and prioritize an appropriate treatment, such as revising the policy or strengthening controls.

Community Discussion

No comments yet. Be the first to start the discussion!