ExamGecko
Question list
Search
Search

Question 131 - CISM discussion

Report
Export

IT projects have gone over budget with too many security controls being added post-production. Which of the following would MOST help to ensure that relevant controls are applied to a project?

A.
Involving information security at each stage of project management
Answers
A.
Involving information security at each stage of project management
B.
Identifying responsibilities during the project business case analysis
Answers
B.
Identifying responsibilities during the project business case analysis
C.
Creating a data classification framework and providing it to stakeholders
Answers
C.
Creating a data classification framework and providing it to stakeholders
D.
Providing stakeholders with minimum information security requirements
Answers
D.
Providing stakeholders with minimum information security requirements
Suggested answer: A

Explanation:

The best way to ensure that relevant controls are applied to a project is to involve information security at each stage of project management. This will help to identify and address the security risks and requirements of the project from the beginning, and to integrate security controls into the project design, development, testing, and implementation. This will also help to avoid adding unnecessary or ineffective controls post-production, which can increase the project cost and complexity, and reduce the project performance and quality. By involving information security at each stage of project management, the information security manager can ensure that the project delivers the expected security value and aligns with the organization's security strategy and objectives.Reference= CISM Review Manual 15th Edition, page 41.

asked 01/10/2024
Denis Mourghen
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first