ExamGecko
Question list
Search
Search

Question 79 - CISM discussion

Report
Export

An information security manager is reporting on open items from the risk register to senior management. Which of the following is MOST important to communicate with regard to these risks?

A.
Responsible entities
Answers
A.
Responsible entities
B.
Key risk indicators (KRIS)
Answers
B.
Key risk indicators (KRIS)
C.
Compensating controls
Answers
C.
Compensating controls
D.
Potential business impact
Answers
D.
Potential business impact
Suggested answer: D

Explanation:

The most important information to communicate with regard to the open items from the risk register to senior management is the potential business impact of these risks. The potential business impact is the estimated consequence or loss that the organization may suffer if the risk materializes or occurs. The potential business impact can be expressed in quantitative or qualitative terms, such as financial, operational, reputational, legal, or strategic impact. Communicating the potential business impact of the open items from the risk register helps senior management to understand the severity and urgency of these risks, and to prioritize the risk response actions and resources accordingly. Communicating the potential business impact also helps senior management to align the risk management objectives and activities with the business objectives and strategies, and to ensure that the risk appetite and tolerance of the organization are respected and maintained.

Reference= CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Assessment, page 831; CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Reporting, page 1012.

asked 01/10/2024
Lyboth Ntsana
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first