ExamGecko
Question list
Search
Search

Question 490 - CISM discussion

Report
Export

When integrating security risk management into an organization it is MOST important to ensure:

A.
business units approve the risk management methodology.
Answers
A.
business units approve the risk management methodology.
B.
the risk treatment process is defined.
Answers
B.
the risk treatment process is defined.
C.
information security policies are documented and understood.
Answers
C.
information security policies are documented and understood.
D.
the risk management methodology follows an established framework.
Answers
D.
the risk management methodology follows an established framework.
Suggested answer: A

Explanation:

When integrating security risk management into an organization, it is most important to ensure that the risk management methodology follows an established framework, such as ISO 31000, NIST SP 800-30, or COBIT. This is because a framework provides a consistent and structured approach to identify, assess, treat, and monitor risks, and to align the risk management process with the organization's objectives, culture, and governance. A framework also helps to ensure compliance with relevant standards and regulations, and to facilitate communication and reporting of risks to stakeholders.

asked 01/10/2024
CHING SHENG WU
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first