ExamGecko
Question list
Search
Search

Question 268 - CISM discussion

Report
Export

Which of the following is the BEST justification for making a revision to a password policy?

A.
Industry best practice
Answers
A.
Industry best practice
B.
A risk assessment
Answers
B.
A risk assessment
C.
Audit recommendation
Answers
C.
Audit recommendation
D.
Vendor recommendation
Answers
D.
Vendor recommendation
Suggested answer: B

Explanation:

A risk assessment should be conducted in order to identify the potential risks associated with a particular system or process, and to determine the best way to mitigate those risks. Making a revision to a password policy based on the results of a risk assessment is the best way to ensure that the policy is effective and secure.

According to the Certified Information Security Manager (CISM) Study manual, the BEST justification for making a revision to a password policy is a risk assessment. A risk assessment enables an organization to identify and evaluate the risks to its information assets and determine the appropriate measures to mitigate those risks, including password policies. Password policies should be based on the risks to the organization's information assets and the level of protection needed.

asked 01/10/2024
Vaniko Batiashvili
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first