ExamGecko
Question list
Search
Search

Question 496 - CISM discussion

Report
Export

To effectively manage an organization's information security risk, it is MOST important to:

A.
assign risk management responsibility to an experienced consultant.
Answers
A.
assign risk management responsibility to an experienced consultant.
B.
periodically identify and correct new systems vulnerabilities.
Answers
B.
periodically identify and correct new systems vulnerabilities.
C.
establish and communicate risk tolerance.
Answers
C.
establish and communicate risk tolerance.
D.
benchmark risk scenarios against peer organizations.
Answers
D.
benchmark risk scenarios against peer organizations.
Suggested answer: C

Explanation:

To effectively manage an organization's information security risk, it is most important to establish and communicate risk tolerance, which is the level of risk that the organization is willing to accept or bear. By establishing and communicating risk tolerance, the organization can align its risk management strategy and objectives with its business goals and values, and ensure that the risk management activities and decisions are consistent and appropriate across the organization.

asked 01/10/2024
Mustafa Hussien
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first