Certified Information Security Manager (CISM)Information Security ProgramEasy
A CISO is establishing an information security program for a global organization with diverse regulatory requirements across multiple jurisdictions. Which of the following is the MOST critical initial step to ensure the program's long-term success and compliance?
- ADeveloping a detailed incident response plan for high-severity security incidents.
- BDeploying advanced security technologies such as Security Information and Event Management (SIEM) systems.
- CImplementing a standardized security awareness training program for all employees.
- DConducting a comprehensive legal and regulatory landscape analysis to identify applicable requirements.
Show answer & explanationAnswer & explanation
Correct answer: D. Conducting a comprehensive legal and regulatory landscape analysis to identify applicable requirements.
Before any technical implementations or awareness programs, understanding the legal and regulatory landscape is paramount. This foundational step ensures the security program is built upon a compliant and legally sound basis, especially for a global organization.
Why the other options are wrong
- A. An incident response plan is crucial but comes after establishing the program's foundational legal, regulatory, and architectural components.
- B. Deploying technologies is a tactical implementation that should follow strategic planning based on identified requirements.
- C. While important, security awareness training is a subsequent step after understanding the foundational legal and regulatory needs.
Regulatory Compliance Foundation
The initial and essential process of identifying and understanding all applicable laws, regulations, and standards that an organization must adhere to, forming the bedrock of its information security program.
- Crucial for global organizations.
- Precedes technical and procedural implementations.
- Ensures legal and ethical operation.
Memory trick: Legal Lens Leads to Lasting Laws.