ExamGecko
Question list
Search
Search

Question 322 - CISM discussion

Report
Export

Which of the following is the BEST justification for making a revision to a password policy?

A.
Vendor recommendation
Answers
A.
Vendor recommendation
B.
Audit recommendation
Answers
B.
Audit recommendation
C.
A risk assessment
Answers
C.
A risk assessment
D.
Industry best practice
Answers
D.
Industry best practice
Suggested answer: C

Explanation:

The best justification for making a revision to a password policy is a risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a risk assessment, the organization can determine the appropriate level of security controls and measures to protect its information assets and systems, including password policies. A risk assessment can also help identify any gaps or weaknesses in the existing password policy, and provide recommendations for improvement based on the organization's risk appetite and tolerance. The other options are not the best justification for making a revision to a password policy, although they may be some inputs or outputs of the risk assessment process. A vendor recommendation is an external source of advice or guidance that may or may not be relevant or applicable to the organization's specific context and needs. A vendor recommendation should not be followed blindly without conducting a risk assessment to evaluate its suitability and effectiveness. An audit recommendation is an internal source of feedback or suggestion that may or may not be accurate or complete. An audit recommendation should not be implemented without conducting a risk assessment to verify its validity and feasibility. An industry best practice is a general standard or guideline that may or may not reflect the organization's unique characteristics and requirements. An industry best practice should not be adopted without conducting a risk assessment to customize it according to the organization's goals and priorities

asked 01/10/2024
Kazi Basit
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first