ExamGecko
Question list
Search
Search

Question 318 - CISM discussion

Report
Export

A risk owner has accepted a large amount of risk due to the high cost of controls. Which of the following should be the information security manager's PRIMARY focus in this situation?

A.
Establishing a strong ongoing risk monitoring process
Answers
A.
Establishing a strong ongoing risk monitoring process
B.
Presenting the risk profile for approval by the risk owner
Answers
B.
Presenting the risk profile for approval by the risk owner
C.
Conducting an independent review of risk responses
Answers
C.
Conducting an independent review of risk responses
D.
Updating the information security standards to include the accepted risk
Answers
D.
Updating the information security standards to include the accepted risk
Suggested answer: A

Explanation:

The information security manager's PRIMARY focus in this situation should be establishing a strong ongoing risk monitoring process, which is the process of tracking and evaluating the changes in the risk environment, the effectiveness of the risk responses, and the impact of the residual risk on the organization. A strong ongoing risk monitoring process can help the information security manager to identify any deviations from the expected risk level, to report any significant changes or issues to the risk owner and other stakeholders, and to recommend any adjustments or improvements to the risk management strategy. Presenting the risk profile for approval by the risk owner is not the primary focus in this situation, as it is a step that should be done before the risk owner accepts the risk, not after. Conducting an independent review of risk responses is not the primary focus in this situation, as it is a quality assurance activity that can be performed by an external auditor or a third-party expert, not by the information security manager.Updating the information security standards to include the accepted risk is not the primary focus in this situation, as it is a documentation activity that does not address the ongoing monitoring and reporting of the risk.Reference= CISM Review Manual, 16th Edition, page 2281; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 1022

asked 01/10/2024
Ubeydullah Kara
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first