ExamGecko
Question list
Search
Search

Question 137 - CISM discussion

Report
Export

In an organization with a rapidly changing environment, business management has accepted an information security risk. It is MOST important for the information security manager to ensure:

A.
change activities are documented.
Answers
A.
change activities are documented.
B.
the rationale for acceptance is periodically reviewed.
Answers
B.
the rationale for acceptance is periodically reviewed.
C.
the acceptance is aligned with business strategy.
Answers
C.
the acceptance is aligned with business strategy.
D.
compliance with the risk acceptance framework.
Answers
D.
compliance with the risk acceptance framework.
Suggested answer: B

Explanation:

= In an organization with a rapidly changing environment, the information security risk landscape may also change frequently due to new threats, vulnerabilities, impacts, or controls. Therefore, the information security manager should ensure that the risk acceptance decisions made by the business management are periodically reviewed to verify that they are still valid and aligned with the current risk appetite and tolerance of the organization. The rationale for acceptance should be documented and updated as necessary to reflect the changes in the risk environment and the business objectives. The information security manager should also monitor the accepted risks and report any deviations or issues to the business management and the senior management.

Reference=

CISM Review Manual 15th Edition, page 1131

CISM Review Questions, Answers & Explanations Manual 9th Edition, page 482

CISM Domain 2: Information Risk Management (IRM) [2022 update]3

asked 01/10/2024
Christopher Dawe
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first