ExamGecko
Question list
Search
Search

Question 143 - CISM discussion

Report
Export

An organization needs to comply with new security incident response requirements. Which of the following should the information security manager do FIRST?

A.
Create a business case for a new incident response plan.
Answers
A.
Create a business case for a new incident response plan.
B.
Revise the existing incident response plan.
Answers
B.
Revise the existing incident response plan.
C.
Conduct a gap analysis.
Answers
C.
Conduct a gap analysis.
D.
Assess the impact to the budget,
Answers
D.
Assess the impact to the budget,
Suggested answer: C

Explanation:

Before implementing any changes to the security incident response plan, the information security manager should first conduct a gap analysis to identify the current state of the plan and compare it with the new requirements. A gap analysis is a systematic process of evaluating the differences between the current and desired state of a system, process, or program. A gap analysis can help to identify the strengths and weaknesses of the existing plan, the gaps that need to be addressed, the priorities and dependencies of the actions, and the resources and costs involved. A gap analysis can also help to create a business case for the changes and justify the investment.A gap analysis can be conducted using various methods and tools, such as frameworks, standards, benchmarks, questionnaires, interviews, audits, or tests1234.

Reference=

CISM Review Manual 15th Edition, page 1631

CISM certified information security manager study guide, page 452

How To Conduct An Information Security Gap Analysis3

PROACTIVE DETECTION - GOOD PRACTICES GAP ANALYSIS RECOMMENDATIONS4

asked 01/10/2024
Kabi Bashala
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first