Courseiva

CISM Information Security Governance Practice Question

A financial services firm is subject to SOX, PCI DSS, and GDPR. The CISO needs to implement a regulatory change management process. Which THREE steps are essential?

⚠ Common exam trap

The trap is selecting options that sound decisive or cost-saving (enforce immediately, outsource to one vendor) — CISM expects you to recognize that accountability cannot be outsourced and that regulatory changes require risk-based assessment, not blind enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess impact on existing controls

Option A (Assess impact on existing controls) is correct because a regulatory change management process must first perform a gap analysis to determine how new or amended SOX, PCI DSS, and GDPR requirements affect the firm's current control environment, including whether existing PCI DSS requirements or SOX ITGC controls still satisfy the new obligations. Option D (Monitor regulatory updates from authorities) is correct because the process must continuously track publications from bodies such as the SEC (SOX), the PCI Security Standards Council (PCI DSS), and EU supervisory authorities/EDPB (GDPR) to detect changes in time. Option E (Update policies and controls accordingly) is correct because once impact is assessed, the firm must revise its policies, procedures, and technical controls and then validate them through testing to maintain compliance. Option B is incorrect because enforcing all changes immediately regardless of cost ignores risk-based prioritization, budgeting, and change management discipline. Option C is incorrect because outsourcing compliance to a single vendor does not transfer regulatory accountability and creates concentration risk, so it is not an essential step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assess impact on existing controls

    Why this is correct

    Assessing the impact determines which existing controls already satisfy the new requirement and which fall short. This analysis links the detected regulatory change to the firm's control environment, directing remediation effort where SOX, PCI DSS or GDPR compliance gaps actually exist.

  • ✗

    Immediately enforce all changes regardless of cost

    Why it's wrong here

    Enforcing every change immediately bypasses impact assessment, testing and approval, breaking the controlled change process SOX and PCI DSS expect. Emergency change procedures exist for urgent fixes; routine regulatory updates must be assessed, prioritised and scheduled against cost and risk.

  • ✗

    Outsource compliance to a single vendor

    Why it's wrong here

    Outsourcing to one vendor transfers operational tasks but leaves the firm accountable for SOX, PCI DSS and GDPR obligations, and a single provider cannot span three differing regimes. Vendor consolidation suits reducing duplicated tooling; regulatory change management still demands internal ownership, mapping and evidence.

  • ✓

    Monitor regulatory updates from authorities

    Why this is correct

    Continuously tracking regulatory publications from authorities provides the trigger that initiates the whole process. Without this monitoring step, changes to SOX, PCI DSS or GDPR obligations would go undetected, so the firm could not assess or respond to them at all.

  • ✓

    Update policies and controls accordingly

    Why this is correct

    Once a regulatory change is assessed, the affected policies and controls must be revised to close any compliance gap. This satisfies the process requirement by translating the impact assessment into concrete, auditable updates across SOX, PCI DSS and GDPR obligations.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.