ExamGecko
Question list
Search
Search

Question 607 - CISM discussion

Report
Export

Which of the following would provide the BEST input to a business case for a technical solution to address potential system vulnerabilities?

A.
Risk assessment
Answers
A.
Risk assessment
B.
Business impact analysis (BIA)
Answers
B.
Business impact analysis (BIA)
C.
Penetration test results
Answers
C.
Penetration test results
D.
Vulnerability scan results
Answers
D.
Vulnerability scan results
Suggested answer: A

Explanation:

Risk assessment is the BEST input to a business case for a technical solution to address potential system vulnerabilities, because it helps to identify and prioritize the most critical risks that the solution should mitigate or reduce. Risk assessment also helps to evaluate the costs and benefits of the solution in terms of reducing the likelihood and impact of potential threats and incidents.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 47: ''Risk assessment is the process of identifying and analyzing information security risks and determining their potential impact on the enterprise's business objectives.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 48: ''Risk assessment provides input to the business case for information security investments by identifying and prioritizing the most critical risks that need to be addressed and evaluating the costs and benefits of the proposed solutions.''

asked 01/10/2024
Adrian Chirtoc
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first