ExamGecko
Question list
Search
Search

Question 420 - CISM discussion

Report
Export

Management of a financial institution accepted an operational risk that consequently led to the temporary deactivation to a critical monitoring process. Which of the following should be the information security manager's GREATEST concern with this situation?

A.
Impact on compliance risk.
Answers
A.
Impact on compliance risk.
B.
Inability to determine short-term impact.
Answers
B.
Inability to determine short-term impact.
C.
Impact on the risk culture.
Answers
C.
Impact on the risk culture.
D.
Deviation from risk management best practices
Answers
D.
Deviation from risk management best practices
Suggested answer: C

Explanation:

Comprehensive and Detailed Explanation = The impact on the risk culture is the greatest concern for the information security manager, because it reflects the attitude and behavior of the organization towards risk management. If management accepts an operational risk that compromises a critical monitoring process, it may indicate a lack of awareness, commitment, or accountability for risk management. This may erode the trust and confidence of the stakeholders, regulators, and customers, and expose the organization to further risks. The impact on compliance risk, the inability to determine short-term impact, and the deviation from risk management best practices are also important, but they are secondary to the impact on the risk culture.

Reference = CISM Review Manual 15th Edition, page 48. CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, question ID 421.

asked 01/10/2024
Jeffrey Tiffany
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first