ExamGecko
Question list
Search
Search

Question 513 - CISM discussion

Report
Export

An organization is about to purchase a rival organization. The PRIMARY reason for performing information security due diligence prior to making the purchase is to:

A.
determine the security exposures.
Answers
A.
determine the security exposures.
B.
assess the ability to integrate the security department operations.
Answers
B.
assess the ability to integrate the security department operations.
C.
ensure compliance with international standards.
Answers
C.
ensure compliance with international standards.
D.
evaluate the security policy and standards.
Answers
D.
evaluate the security policy and standards.
Suggested answer: A

Explanation:

Information security due diligence is the process of assessing the current state of information security in an organization, identifying any gaps, risks, or vulnerabilities, and estimating the costs and efforts required to remediate them. Performing information security due diligence prior to making the purchase is important to determine the security exposures that may affect the value, reputation, or liability of the organization, as well as the feasibility and compatibility of integrating the security systems and processes of the two organizations.

Reference= CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.22; Information Security Due Diligence Questionnair

asked 01/10/2024
Junaid Sahebzada
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first