Certified Information Security Manager (CISM)Information Security ProgramEasy

A CISO is establishing an information security program for a newly acquired subsidiary. The subsidiary operates in a highly regulated industry. Which of the following should be the CISO's PRIMARY initial consideration to ensure the program's foundation is sound and compliant?

  1. ADeveloping a detailed incident response plan tailored to the subsidiary's existing IT infrastructure.
  2. BInitiating a security awareness training program for all subsidiary employees.
  3. CConducting a comprehensive regulatory and legal compliance assessment specific to the subsidiary's operations.
  4. DImplementing immediate technical controls like firewalls and intrusion detection systems.
Show answer & explanation

Correct answer: C. Conducting a comprehensive regulatory and legal compliance assessment specific to the subsidiary's operations.

For a newly acquired subsidiary in a highly regulated industry, understanding the specific regulatory and legal landscape is paramount. This assessment directly informs the design and priorities of the entire security program, ensuring foundational compliance before other initiatives.

Why the other options are wrong

  • A. An incident response plan is vital, but its effectiveness depends on understanding the assets and regulatory obligations, which are identified through the compliance assessment.
  • B. Security awareness is important for all programs, but it should be informed by the risks and compliance requirements identified through the initial assessment.
  • D. While important, implementing controls without understanding compliance requirements might lead to non-compliance or misdirected effort.

Regulatory Compliance Foundation

Ensuring an information security program adheres to all applicable laws, regulations, and industry standards, especially critical in regulated sectors.

  • Forms the non-negotiable baseline for security.
  • Guides control selection and risk management.
  • Avoids legal penalties and reputational damage.

Memory trick: Regulatory maps guide the security journey's first steps.

More Information Security Program questions