ExamQuestions.com

Register
Login
Certified Information Security Manager Exam Questions

Isaca

Certified Information Security Manager

241 / 500

Question 241:

Because of its importance to the business, an organization wants to quickly implement a technical solution which deviates from the company`s policies. An information security manager should: 

Answer options:

A. conduct a risk assessment and allow or disallow based on the outcome.
B. recommend a risk assessment and implementation only if the residual risks are accepted.
C. recommend against implementation because it violates the company`s policies.
D. recommend revision of current policy.