ExamGecko
Question list
Search
Search

Question 436 - CISM discussion

Report
Export

Which of the following components of an information security risk assessment is MOST valuable to senior management?

A.
Threat profile
Answers
A.
Threat profile
B.
Residual risk
Answers
B.
Residual risk
C.
Return on investment (ROI)
Answers
C.
Return on investment (ROI)
D.
Mitigation actions
Answers
D.
Mitigation actions
Suggested answer: B

Explanation:

Residual risk is the risk that remains after implementing risk mitigation actions.It is the most valuable component for senior management because it helps them to evaluate the effectiveness and efficiency of risk management and make informed decisions about risk acceptance, transfer or avoidance.Reference= CISM Review Manual, 16th Edition, Chapter 2, Section 2.3.41

asked 01/10/2024
Reinhard KOhl
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first