ExamGecko
Question list
Search
Search

Question 590 - CISM discussion

Report
Export

During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:

A.
perform a risk assessment.
Answers
A.
perform a risk assessment.
B.
review the state of security awareness.
Answers
B.
review the state of security awareness.
C.
review information security policies.
Answers
C.
review information security policies.
D.
perform a gap analysis.
Answers
D.
perform a gap analysis.
Suggested answer: A

Explanation:

According to the CISM Review Manual, performing a risk assessment is the most important course of action for an information security manager during the due diligence phase of an acquisition, as it helps to identify and evaluate the potential threats, vulnerabilities and impacts that may affect the information assets of the target organization. A risk assessment also provides the basis for performing a gap analysis, reviewing the information security policies and awareness, and developing a remediation plan.

Reference= CISM Review Manual, 27th Edition, Chapter 3, Section 3.4.1, page 1411.

asked 01/10/2024
gayathri devi
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first