ExamGecko
Question list
Search
Search

Question 551 - CISM discussion

Report
Export

Which of the following is the MOST effective way to identify changes in an information security environment?

A.
Business impact analysis (BIA)
Answers
A.
Business impact analysis (BIA)
B.
Annual risk assessments
Answers
B.
Annual risk assessments
C.
Regular penetration testing
Answers
C.
Regular penetration testing
D.
Continuous monitoring
Answers
D.
Continuous monitoring
Suggested answer: D

Explanation:

Continuous monitoring is the most effective way to identify changes in an information security environment, as it provides ongoing awareness of the security status, vulnerabilities, and threats that may affect the organization's information assets and risk posture. Continuous monitoring also helps to evaluate the performance and effectiveness of the security controls and processes, and to detect and respond to any deviations or incidents in a timely manner.(From CISM Review Manual 15th Edition and NIST Special Publication 800-1371)

asked 01/10/2024
Vidana Weerasinghe
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first