ExamGecko
Question list
Search
Search

Question 167 - CISM discussion

Report
Export

Reevaluation of risk is MOST critical when there is:

A.
resistance to the implementation of mitigating controls.
Answers
A.
resistance to the implementation of mitigating controls.
B.
a management request for updated security reports.
Answers
B.
a management request for updated security reports.
C.
a change in security policy.
Answers
C.
a change in security policy.
D.
a change in the threat landscape.
Answers
D.
a change in the threat landscape.
Suggested answer: D

Explanation:

= Reevaluation of risk is a vital aspect of the risk management process that helps organizations to identify and analyze new or evolving threats, vulnerabilities, and impacts on their assets, and implement the necessary controls to mitigate them. Reevaluation of risk is most critical when there is a change in the threat landscape, which refers to the external and internal factors that influence the likelihood and severity of potential attacks on the organization's information assets. A change in the threat landscape may be caused by various factors, such as technological innovations, geopolitical events, cybercrime trends, regulatory changes, or organizational changes. A change in the threat landscape may introduce new risks or alter the existing risk profile of the organization, requiring a reassessment of the risk appetite, tolerance, and strategy. Reevaluation of risk helps the organization to adapt to the changing threat landscape and ensure that the information security program remains effective, efficient, and aligned with the business objectives.

Reference=

CISM Review Manual 15th Edition, page 1131

CISM Domain 2: Information Risk Management (IRM) [2022 update]2

Reevaluation of Risk | CISM Exam Question Answer | ISACA3

asked 01/10/2024
William Kerr
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first