ExamGecko
Question list
Search
Search

Question 585 - CISM discussion

Report
Export

To inform a risk treatment decision, which of the following should the information security manager compare with the organization's risk appetite?

A.
Level of residual risk
Answers
A.
Level of residual risk
B.
Level of risk treatment
Answers
B.
Level of risk treatment
C.
Configuration parameters
Answers
C.
Configuration parameters
D.
Gap analysis results
Answers
D.
Gap analysis results
Suggested answer: A

Explanation:

The information security manager should compare the level of residual risk with the organization's risk appetite to inform a risk treatment decision. Residual risk is the risk that remains after applying the risk treatment options, such as avoiding, transferring, mitigating, or accepting the risk. Risk appetite is the amount of risk that the organization is willing to accept to achieve its objectives. The information security manager should ensure that the residual risk is within the risk appetite, and if not, apply additional risk treatment measures or escalate the risk to the senior management for approval.

Reference= CISM Review Manual, 16th Edition eBook1, Chapter 2: Information Risk Management, Section: Risk Management, Subsection: Risk Treatment, Page 102.

asked 01/10/2024
Peter Jennings
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first