ExamGecko
Question list
Search
Search

Question 291 - CISM discussion

Report
Export

Management has announced the acquisition of a new company. The information security manager of the parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies. To BEST address this concern, the information security manager should:

A.
review access rights as the acquisition integration occurs.
Answers
A.
review access rights as the acquisition integration occurs.
B.
perform a risk assessment of the access rights.
Answers
B.
perform a risk assessment of the access rights.
C.
escalate concerns for conflicting access rights to management.
Answers
C.
escalate concerns for conflicting access rights to management.
D.
implement consistent access control standards.
Answers
D.
implement consistent access control standards.
Suggested answer: B

Explanation:

Performing a risk assessment of the access rights is the best way to address the concern of conflicting access rights during the integration of two companies. A risk assessment will help to identify and prioritize the threats and vulnerabilities that affect the access rights of both companies, as well as the potential impact and likelihood of information exposure. A risk assessment will also provide a basis for selecting and evaluating the controls to mitigate the risks. According to NIST, a risk assessment is an essential component of risk management and should be performed before implementing any security controls1. The other options are not the best ways to address the concern of conflicting access rights during the integration of two companies, but rather possible subsequent actions based on the risk assessment. Reviewing access rights as the acquisition integration occurs may be too late or too slow to prevent information exposure. Escalating concerns for conflicting access rights to management may not be effective without evidence or recommendations from a risk assessment. Implementing consistent access control standards may not be feasible or desirable for different systems or business units.

Reference: 1: NIST SP 800-30 Rev. 1 Guide for Conducting Risk Assessments 2: M&A integration strategy is crucial for deal success but remains difficult: PwC 3: The 10 steps to successful M&A integration | Bain & Company : Cracking the code to successful post-merger integration

asked 01/10/2024
Albert Hidalgo Bassons
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first