ExamGecko
Question list
Search
Search

Question 124 - CISM discussion

Report
Export

Which of the following is the PRIMARY reason for granting a security exception?

A.
The risk is justified by the cost to the business.
Answers
A.
The risk is justified by the cost to the business.
B.
The risk is justified by the benefit to security.
Answers
B.
The risk is justified by the benefit to security.
C.
The risk is justified by the cost to security.
Answers
C.
The risk is justified by the cost to security.
D.
The risk is justified by the benefit to the business.
Answers
D.
The risk is justified by the benefit to the business.
Suggested answer: A

Explanation:

= A security exception is a formal authorization to deviate from a security policy, standard, or control, due to a valid business reason or requirement. The primary reason for granting a security exception is that the risk associated with the deviation is justified by the benefit to the business, such as increased efficiency, productivity, customer satisfaction, or competitive advantage. The security exception should be approved by the appropriate authority, such as the senior management or the risk committee, based on a risk assessment and a cost-benefit analysis.The security exception should also be documented, communicated, monitored, and reviewed periodically123.Reference=

1: CISM Review Manual 15th Edition, page 364

2: CISM Practice Quiz, question 1132

3: Security Policy Exception Management, section ''Security Policy Exception Management Process''

asked 01/10/2024
Naveen Kotipalli
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first