ExamGecko
Question list
Search
Search

Question 49 - CISM discussion

Report
Export

An organization is going through a digital transformation process, which places the IT organization in an unfamiliar risk landscape. The information security manager has been tasked with leading the IT risk management process. Which of the following should be given the HIGHEST priority?

A.
Identification of risk
Answers
A.
Identification of risk
B.
Analysis of control gaps
Answers
B.
Analysis of control gaps
C.
Design of key risk indicators (KRIs)
Answers
C.
Design of key risk indicators (KRIs)
D.
Selection of risk treatment options
Answers
D.
Selection of risk treatment options
Suggested answer: A

Explanation:

= Identification of risk is the first and most important step in the IT risk management process, especially when the organization is undergoing a digital transformation that introduces new technologies, processes, and business models. Identification of risk involves determining the sources, causes, and potential consequences of IT-related risks that may affect the organization's objectives, assets, and stakeholders. Identification of risk also helps to establish the risk context, scope, and criteria for the subsequent risk analysis, evaluation, and treatment. Without identifying the risks, the information security manager cannot effectively assess the risk exposure, prioritize the risks, implement appropriate controls, monitor the risk performance, or communicate the risk information to the relevant parties.

Reference= CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Identification, page 841; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 34, page 352.

asked 01/10/2024
Jessica Mahoney
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first