ExamGecko
Question list
Search
Search

Question 529 - CISM discussion

Report
Export

The business value of an information asset is derived from:

A.
the threat profile.
Answers
A.
the threat profile.
B.
its criticality.
Answers
B.
its criticality.
C.
the risk assessment.
Answers
C.
the risk assessment.
D.
its replacement cost.
Answers
D.
its replacement cost.
Suggested answer: B

Explanation:

The business value of an information asset is derived from its criticality, which is the degree of importance or dependency of the asset to the organization's objectives, operations, and stakeholders. The criticality of an information asset can be determined by assessing its impact on the confidentiality, integrity, and availability (CIA) of the information, as well as its sensitivity, classification, and regulatory requirements. The higher the criticality of an information asset, the higher its business value, and the more resources and controls are needed to protect it.

Reference= CISM Review Manual 2022, page 371; CISM Exam Content Outline, Domain 1, Task 1.32; IT Asset Valuation, Risk Assessment and Control Implementation Model1; Managing Data as an Asset3

asked 01/10/2024
Ahmad Zaher Al Ojaili
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first