ExamGecko
Question list
Search
Search

Question 3 - CISM discussion

Report
Export

Which of the following BEST enables an information security manager to determine the comprehensiveness of an organization's information security strategy?

A.
Internal security audit
Answers
A.
Internal security audit
B.
External security audit
Answers
B.
External security audit
C.
Organizational risk appetite
Answers
C.
Organizational risk appetite
D.
Business impact analysis (BIA)
Answers
D.
Business impact analysis (BIA)
Suggested answer: C

Explanation:

The organizational risk appetite is the best indicator of the comprehensiveness of an information security strategy. The risk appetite defines the level of risk that the organization is willing to accept in pursuit of its objectives. The information security strategy should align with the risk appetite and provide a framework for managing the risks that the organization faces. An internal or external security audit can assess the effectiveness of the information security strategy, but not its comprehensiveness.A business impact analysis (BIA) can identify the critical business processes and assets that need to be protected, but not the overall scope and direction of the information security strategy.Reference= CISM Review Manual 2023, page 361; CISM Practice Quiz2

asked 01/10/2024
Gennadiy Volkov
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first