ExamGecko
Question list
Search
Search

Question 136 - CISM discussion

Report
Export

Of the following, who is in the BEST position to evaluate business impacts?

A.
Senior management
Answers
A.
Senior management
B.
Information security manager
Answers
B.
Information security manager
C.
IT manager
Answers
C.
IT manager
D.
Process manager
Answers
D.
Process manager
Suggested answer: D

Explanation:

The process manager is the person who is responsible for overseeing and managing the business processes and functions that are essential for the organization's operations and objectives. The process manager has the most direct and detailed knowledge of the inputs, outputs, dependencies, resources, and performance indicators of the business processes and functions. Therefore, the process manager is in the best position to evaluate the business impacts of a disruption or an incident that affects the availability, integrity, or confidentiality of the information assets and systems that support the business processes and functions. The process manager can identify and quantify the potential losses, damages, or consequences that could result from the disruption or incident, such as revenue loss, customer dissatisfaction, regulatory non-compliance, reputational harm, or legal liability.The process manager can also provide input and feedback to the information security manager and the senior management on the business continuity and disaster recovery plans, the risk assessment and treatment, and the security controls and measures that are needed to protect and recover the business processes and functions.Reference= CISM Review Manual 15th Edition, page 2301; CISM Practice Quiz, question 1302

asked 01/10/2024
Daniel Kuzmanovski
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first