ExamGecko
Question list
Search
Search

Question 144 - CISM discussion

Report
Export

Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?

A.
Security policy
Answers
A.
Security policy
B.
Risk management framework
Answers
B.
Risk management framework
C.
Risk appetite
Answers
C.
Risk appetite
D.
Security standards
Answers
D.
Security standards
Suggested answer: C

Explanation:

= Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives. It is a key factor that influences the information security strategy and objectives, as well as the selection and implementation of security controls. Risk appetite must be defined in order for an information security manager to evaluate the appropriateness of controls currently in place, as it provides the basis for determining whether the controls are sufficient, excessive, or inadequate to address the risks faced by the organization. The information security manager should align the controls with the risk appetite of the organization, ensuring that the controls are effective, efficient, and economical.Reference= CISM Review Manual 15th Edition, page 29, page 31.

asked 01/10/2024
Susan Brady
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first