ExamGecko
Question list
Search
Search

Question 327 - CISM discussion

Report
Export

What should be an information security manager's FIRST step when developing a business case for a new intrusion detection system (IDS) solution?

A.
Define the issues to be addressed.
Answers
A.
Define the issues to be addressed.
B.
Perform a cost-benefit analysis.
Answers
B.
Perform a cost-benefit analysis.
C.
Calculate the total cost of ownership (TCO).
Answers
C.
Calculate the total cost of ownership (TCO).
D.
Conduct a feasibility study.
Answers
D.
Conduct a feasibility study.
Suggested answer: A

Explanation:

The first step when developing a business case for a new intrusion detection system (IDS) solution is to define the issues to be addressed. A business case is a document that provides the rationale and justification for initiating a project or investment. It typically includes information such as the problem statement, the objectives, the alternatives, the costs and benefits, the risks and assumptions, and the expected outcomes. The first step in developing a business case is to define the issues to be addressed, which means identifying and describing the current situation, the problems or challenges faced by the organization, and the needs or opportunities for improvement. By defining the issues to be addressed, the information security manager can establish the scope and purpose of the business case, and provide a clear and compelling problem statement that explains why a new IDS solution is needed. The other options are not the first step when developing a business case for a new IDS solution, although they may be part of the subsequent steps. Performing a cost-benefit analysis is a step that involves comparing the costs and benefits of different alternatives, including the new IDS solution and the status quo. A cost-benefit analysis can help evaluate and justify the feasibility and desirability of each alternative, and support the decision-making process. Calculating the total cost of ownership (TCO) is a step that involves estimating the direct and indirect costs associated with acquiring, operating, maintaining, and disposing of an asset or a system over its entire life cycle. A TCO calculation can help determine the long-term financial implications of investing in a new IDS solution, and compare it with other alternatives. Conducting a feasibility study is a step that involves assessing the technical, operational, legal, and economic aspects of implementing a project or an investment. A feasibility study can help identify and mitigate any potential issues or risks that may affect the success of the project or investment, and provide recommendations for improvement

asked 01/10/2024
Hassene SAADI
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first