ExamGecko
Question list
Search
Search

Question 138 - CISM discussion

Report
Export

Management decisions concerning information security investments will be MOST effective when they are based on:

A.
a process for identifying and analyzing threats and vulnerabilities.
Answers
A.
a process for identifying and analyzing threats and vulnerabilities.
B.
an annual loss expectancy (ALE) determined from the history of security events,
Answers
B.
an annual loss expectancy (ALE) determined from the history of security events,
C.
the reporting of consistent and periodic assessments of risks.
Answers
C.
the reporting of consistent and periodic assessments of risks.
D.
the formalized acceptance of risk analysis by management,
Answers
D.
the formalized acceptance of risk analysis by management,
Suggested answer: C

Explanation:

Management decisions concerning information security investments will be most effective when they are based on the reporting of consistent and periodic assessments of risks. This will help management to understand the current and emerging threats, vulnerabilities, and impacts that affect the organization's information assets and business processes. It will also help management to prioritize the allocation of resources and funding for the most critical and cost-effective security controls and solutions. The reporting of consistent and periodic assessments of risks will also enable management to monitor the performance and effectiveness of the information security program, and to adjust the security strategy and objectives as needed.Reference= CISM Review Manual 15th Edition, page 28.

asked 01/10/2024
Vaibhav Somani
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first