ExamGecko
Question list
Search
Search

Question 13 - Cybersecurity Audit discussion

Report
Export

Which of the following would provide the BEST basis for allocating proportional protection activities when comprehensive classification is not feasible?

A.
Single classification level allocation
Answers
A.
Single classification level allocation
B.
Business process re-engineering
Answers
B.
Business process re-engineering
C.
Business dependency assessment
Answers
C.
Business dependency assessment
D.
Comprehensive cyber insurance procurement
Answers
D.
Comprehensive cyber insurance procurement
Suggested answer: C

Explanation:

The BEST basis for allocating proportional protection activities when comprehensive classification is not feasible is a business dependency assessment. This is because a business dependency assessment helps to identify the criticality and sensitivity of business processes and their supporting assets, based on their contribution to the organization's objectives and value proposition. This allows for prioritizing protection activities according to the level of risk and impact. The other options are not as effective as a business dependency assessment, because they either use a single classification level allocation (A), which does not account for different levels of risk and impact; require a significant amount of time and resources to perform a business process re-engineering (B); or rely on external parties to cover potential losses without reducing the likelihood or impact of incidents (D).

asked 18/09/2024
Arvin Lee
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first