CISM Information Security Governance Practice Question
A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?
⚠ Common exam trap
The trap is selecting options that sound decisive or cost-saving (enforce immediately, outsource to one vendor) — CISM expects you to recognize that accountability cannot be outsourced and that regulatory changes require risk-based assessment, not blind enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess impact on existing controls
Option A (Assess impact on existing controls) is correct because a regulatory change management process must first perform a gap analysis to determine how new or amended SOX, PCI DSS, and GDPR requirements affect the firm's current control environment, including whether existing PCI DSS requirements or SOX ITGC controls still satisfy the new obligations. Option D (Monitor regulatory updates from authorities) is correct because the process must continuously track publications from bodies such as the SEC (SOX), the PCI Security Standards Council (PCI DSS), and EU supervisory authorities/EDPB (GDPR) to detect changes in time. Option E (Update policies and controls accordingly) is correct because once impact is assessed, the firm must revise its policies, procedures, and technical controls and then validate them through testing to maintain compliance. Option B is incorrect because enforcing all changes immediately regardless of cost ignores risk-based prioritization, budgeting, and change management discipline. Option C is incorrect because outsourcing compliance to a single vendor does not transfer regulatory accountability and creates concentration risk, so it is not an essential step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assess impact on existing controls
Why this is correct
Assessing the impact determines which existing controls already satisfy the new requirement and which fall short. This analysis links the detected regulatory change to the firm's control environment, directing remediation effort where SOX, PCI DSS or GDPR compliance gaps actually exist.
- ✗
Immediately enforce all changes regardless of cost
Why it's wrong here
Enforcing every change immediately bypasses impact assessment, testing and approval, breaking the controlled change process SOX and PCI DSS expect. Emergency change procedures exist for urgent fixes; routine regulatory updates must be assessed, prioritised and scheduled against cost and risk.
- ✗
Outsource compliance to a single vendor
Why it's wrong here
Outsourcing to one vendor transfers operational tasks but leaves the firm accountable for SOX, PCI DSS and GDPR obligations, and a single provider cannot span three differing regimes. Vendor consolidation suits reducing duplicated tooling; regulatory change management still demands internal ownership, mapping and evidence.
- ✓
Monitor regulatory updates from authorities
Why this is correct
Continuously tracking regulatory publications from authorities provides the trigger that initiates the whole process. Without this monitoring step, changes to SOX, PCI DSS or GDPR obligations would go undetected, so the firm could not assess or respond to them at all.
- ✓
Update policies and controls accordingly
Why this is correct
Once a regulatory change is assessed, the affected policies and controls must be revised to close any compliance gap. This satisfies the process requirement by translating the impact assessment into concrete, auditable updates across SOX, PCI DSS and GDPR obligations.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.