ExamGecko
Question list
Search
Search

Question 424 - CISM discussion

Report
Export

Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?

A.
Alignment with industry benchmarks
Answers
A.
Alignment with industry benchmarks
B.
Results of business impact analyses (BIAs)
Answers
B.
Results of business impact analyses (BIAs)
C.
Possibility of reputational loss due to incidents
Answers
C.
Possibility of reputational loss due to incidents
D.
Availability of security budget
Answers
D.
Availability of security budget
Suggested answer: B

Explanation:

The priority for implementing security controls should be based on the results of BIAs, which identify the criticality and recovery requirements of business processes and the supporting information assets. BIAs help to align security controls with business needs and objectives, and to optimize the allocation of security resources.Alignment with industry benchmarks, possibility of reputational loss due to incidents, and availability of security budget are important factors, but they are not the most important consideration for determining the priority for implementing security controls.Reference= CISM Review Manual, 16th Edition, page 971; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 2672

asked 01/10/2024
Syed Azar
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first