ExamGecko
Question list
Search
Search

Question 232 - CISM discussion

Report
Export

During the initiation phase of the system development life cycle (SDLC) for a software project, information security activities should address:

A.
baseline security controls.
Answers
A.
baseline security controls.
B.
benchmarking security metrics.
Answers
B.
benchmarking security metrics.
C.
security objectives.
Answers
C.
security objectives.
D.
cost-benefit analyses.
Answers
D.
cost-benefit analyses.
Suggested answer: C

Explanation:

During the initiation phase of the system development life cycle (SDLC) for a software project, information security activities should address security objectives, which are derived from the business objectives and the risk assessment. Security objectives define the desired level of protection for the system and its data, and guide the selection of security controls in later phases. Baseline security controls are predefined sets of security requirements that apply to common types of systems or environments. Benchmarking security metrics is a process of comparing the performance of security processes or controls against a standard or best practice.Cost-benefit analyses are used to evaluate the feasibility and effectiveness of security controls, and are usually performed in the acquisition/development phase or the implementation phase of the SDLC.Reference= CISM Review Manual, 16th Edition, page 1021; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 772

Learn more:

1. isaca.org2. amazon.com3. gov.uk

asked 01/10/2024
Emmanuel Yeboah
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first