ExamGecko
Question list
Search
Search

Question 573 - CISM discussion

Report
Export

The PRIMARY reason for creating a business case when proposing an information security project is to:

A.
articulate inherent risks.
Answers
A.
articulate inherent risks.
B.
provide demonstrated return on investment (ROI).
Answers
B.
provide demonstrated return on investment (ROI).
C.
establish the value of the project in relation to business objectives.
Answers
C.
establish the value of the project in relation to business objectives.
D.
gain key business stakeholder engagement.
Answers
D.
gain key business stakeholder engagement.
Suggested answer: C

Explanation:

The primary reason for creating a business case when proposing an information security project is to establish the value of the project in relation to the business objectives and to justify the investment required. A business case should demonstrate how the project aligns with the organization's strategy, goals, and mission, and how it supports the business processes and functions. A business case should also include the expected benefits, costs, risks, and alternatives of the project, and provide a clear rationale for choosing the preferred option.

Reference= CISM Review Manual, 16th Edition eBook1, Chapter 1: Information Security Governance, Section: Information Security Strategy, Subsection: Business Case Development, Page 33.

asked 01/10/2024
Troy Borders
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first