First Action for Information Security Budget Cuts
Senior management has requested a budget cut for the information security program in the coming fiscal year. Which of the following should be the information security manager's FIRST course of action?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the governance sequence for responding to resource changes, where the trap is jumping to communication or mitigation before assessing the actual impact on risk.
When facing a budget cut, the information security manager must first analyze the impact on the program's risk posture. Community consensus confirms that assessing implications is required before communicating changes or re-prioritizing resources.
Selecting D (Re-prioritize) is a common error because candidates instinctively want to solve the resource shortage immediately, but analysis is required to inform that re-prioritization.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Analyzing the impact is the foundational step in risk management and governance. Before any adjustments can be made to the program, the manager must understand the specific risks introduced by the budget reduction. This analysis provides the data needed to justify the budget or accept the residual risk.Why the Other Options Are Wrong
Advising business unit heads (B) is premature without knowing the specific impacts. Evaluating cost savings (C) is a mitigation strategy that happens after the impact is known. Re-prioritizing operations (D) is a necessary action, but it cannot be done effectively without first analyzing which areas will suffer most from the cuts.Community Comment Notes
Community members strongly support A, noting it is the "critical first step." Comments highlight that the manager must assess how the cut affects initiatives and controls to make informed decisions subsequently.Official Reference
- ISACA CISM Review Manual, 2024 (Domain 1: Information Security Governance)
- https://www.isaca.org/resources/certified-information-security-manager
Exam Strategy
For "First" questions involving changes in resources, always look for the assessment or analysis option. Never select a solution or communication option until the impact on risk has been quantified.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →