CISM Certified Information Security Manager – Question0020

Which of the following requirements would have the lowest level of priority in information security?

A.
Technical
B. Regulatory
C. Privacy
D. Business

Correct Answer: A

Explanation:

Explanation:
Information security priorities may, at times, override technical specifications, which then must be rewritten to conform to minimum security standards. Regulatory and privacy requirements are government-mandated and, therefore, not subject to override. The needs of the business should always take precedence in deciding information security priorities.