Yeah, this comes down to whether the roadmap's already agreed on. If the roadmap is done, then D makes sense since you need a detailed project plan to start executing. But if exec consensus wasn’t secured, A could sneak in as the right move. Pretty sure on D unless the question’s hiding that detail somewhere.
Q: 8
Which of the following should an information security manager do NEXT after creating a roadmap to
execute the strategy for an information security program?
Options
Discussion
Its D, not A. Project plan comes after the roadmap, seen similar on practice exams.
Option B
D is right here. Once the roadmap is set, you need to break it down into an actual project plan so implementation can begin. That's generally the CISM flow, I think, but open to other views.
Probably D. After you’ve built the roadmap, the standard next move in most frameworks and from the CISM official guide is to break that down into a project plan so you can actually implement. Makes sense unless they meant you still needed approval. Anyone disagree?
B not D
D imo. Once the roadmap is set, building a project plan is usually next to get things actually moving.
Be respectful. No spam.
Question 8 of 35