ExamGecko
Question list
Search
Search

Question 287 - CISM discussion

Report
Export

When developing a business case to justify an information security investment, which of the following would BEST enable an informed decision by senior management?

A.
The information security strategy
Answers
A.
The information security strategy
B.
Losses due to security incidents
Answers
B.
Losses due to security incidents
C.
The results of a risk assessment
Answers
C.
The results of a risk assessment
D.
Security investment trends in the industry
Answers
D.
Security investment trends in the industry
Suggested answer: C

Explanation:

The results of a risk assessment would best enable an informed decision by senior management when developing a business case to justify an information security investment. A risk assessment will help to identify and prioritize the threats and vulnerabilities that affect the organization's assets and processes, as well as the potential impact and likelihood of occurrence. A risk assessment will also provide a basis for selecting and evaluating the effectiveness of controls to mitigate the risks. According to CISA, developing a business case for security will be based on an in-depth understanding of organizational vulnerabilities, operational priorities, and return on investment1. The information security strategy, losses due to security incidents, and security investment trends in the industry are possible inputs or outputs of a risk assessment, but they are not sufficient to enable an informed decision by senior management.

Reference: 1: The Business Case for Security - CISA 2: The Business Case for Security | CISA 3: #HowTo: Build a Business Case for Cybersecurity Investment 4: Making the Business Case for Information Security

asked 01/10/2024
stefano atzei
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first