CISM Certified Information Security Manager – Question0634

When a proposed system change violates an existing security standard, the conflict would be BEST resolved by:

A.
calculating the residual risk.
B. enforcing the security standard.
C. redesigning the system change.
D. implementing mitigating controls.

Correct Answer: D