ExamGecko
Question list
Search
Search

Question 306 - CISM discussion

Report
Export

Which of the following should be the FIRST step in developing an information security strategy?

A.
Perform a gap analysis based on the current state
Answers
A.
Perform a gap analysis based on the current state
B.
Create a roadmap to identify security baselines and controls.
Answers
B.
Create a roadmap to identify security baselines and controls.
C.
Identify key stakeholders to champion information security.
Answers
C.
Identify key stakeholders to champion information security.
D.
Determine acceptable levels of information security risk.
Answers
D.
Determine acceptable levels of information security risk.
Suggested answer: A

Explanation:

The FIRST step in developing an information security strategy is to perform a gap analysis based on the current state of the organization's information security posture. A gap analysis is a systematic process of comparing the current state with the desired state and identifying the gaps or deficiencies that need to be addressed. A gap analysis helps to establish a baseline for the information security strategy, as well as to prioritize the actions and resources needed to achieve the strategic objectives.A gap analysis also helps to align the information security strategy with the organizational goals and strategies, as well as to ensure compliance with relevant standards and regulations.Reference= CISM Review Manual, 16th Edition, page 331; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 162

first step in developing an information security strategy is to conduct a risk-aware and comprehensive inventory of your company's context, including all digital assets, employees, and vendors. Then you need to know about the threat environment and which types of attacks are a threat to your company1. This is similar to performing a gap analysis based on the current state3.

asked 01/10/2024
Amin Dashti
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first