ExamGecko
Question list
Search
Search

Question 462 - CISM discussion

Report
Export

Which of the following would BEST guide the development and maintenance of an information security program?

A.
A business impact assessment
Answers
A.
A business impact assessment
B.
A comprehensive risk register
Answers
B.
A comprehensive risk register
C.
An established risk assessment process
Answers
C.
An established risk assessment process
D.
The organization's risk appetite
Answers
D.
The organization's risk appetite
Suggested answer: D

Explanation:

According to the CISM Manual, the organization's risk appetite is the amount and type of risk that the organization is willing to accept in order to achieve its objectives1.The organization's risk appetite should guide the development and maintenance of an information security program, as it determines the level of security controls, resources, and activities that are needed to protect the organization's assets and operations1.

The CISM Manual states that ''the information security program should be aligned with the organization's risk appetite, which reflects its tolerance for risk and its strategic objectives'' (IR 8288A)1.The information security program should also consider other factors that influence the organization's risk appetite, such as its mission, vision, values, culture, stakeholders, regulations, standards, guidelines, and best practices1.

The CISM Manual also provides guidance on how to develop and maintain an information security program based on the organization's risk appetite.It recommends using a process that involves identifying, analyzing, evaluating, treating, monitoring, and reviewing risks that affect the organization's information assets1.It also suggests using a framework or model that supports the development of an information security program based on the organization's risk appetite (e.g., ISO/IEC 27001)1.

asked 01/10/2024
Sébastien PIERRE
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first