Certified Information Security Manager (CISM) — Question 1003
Senior management has requested a budget cut for the information security program in the coming fiscal year. Which of the following should be the information security manager's FIRST course of action?
Answer options
- A. Analyze the impact to the information security program.
- B. Advise business unit heads of potential changes to the information security program.
- C. Evaluate cost savings within existing implementations.
- D. Re-prioritize information security implementation and operations.
Correct answer: A
Explanation
The correct answer is A because understanding the impact of budget cuts on the information security program is crucial for making informed decisions. Options B, C, and D are all important actions but should be taken after analyzing the potential effects of the budget reduction.