ExamGecko
Question list
Search
Search

Question 603 - CISM discussion

Report
Export

Which of the following events is MOST likely to require an organization to revisit its information security framework?

A.
New services offered by IT
Answers
A.
New services offered by IT
B.
Changes to the risk landscape
Answers
B.
Changes to the risk landscape
C.
A recent cybersecurity attack
Answers
C.
A recent cybersecurity attack
D.
A new technology implemented
Answers
D.
A new technology implemented
Suggested answer: B

Explanation:

Changes to the risk landscape are the most likely events to require an organization to revisit its information security framework, because they may affect the organization's risk appetite, risk tolerance, risk profile, and risk treatment strategies. The information security framework should be aligned with the organization's business objectives and risk management approach, and should be reviewed and updated regularly to reflect the changing internal and external environment.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 35: ''The information security framework should be reviewed and updated regularly to ensure that it remains aligned with the enterprise's business objectives and risk management approach and reflects the changing internal and external environment.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: ''Changes in the risk landscape may require the enterprise to revisit its risk appetite, risk tolerance, risk profile, and risk treatment strategies.''

asked 01/10/2024
Vladimir Litvinenko
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first