ExamGecko
Question list
Search
Search

Question 608 - CISM discussion

Report
Export

To inform a risk treatment decision, which of the following should the information security manager compare with the organization's risk appetite?

A.
Gap analysis results
Answers
A.
Gap analysis results
B.
Level of residual risk
Answers
B.
Level of residual risk
C.
Level of risk treatment
Answers
C.
Level of risk treatment
D.
Configuration parameters
Answers
D.
Configuration parameters
Suggested answer: B

Explanation:

Level of residual risk is the amount of risk that remains after applying risk treatment options, such as avoidance, mitigation, transfer, or acceptance. The information security manager should compare the level of residual risk with the organization's risk appetite, which is the amount of risk that the organization is willing to accept in pursuit of its objectives. The comparison will help to determine whether the risk treatment options are sufficient, excessive, or inadequate, and whether further actions are needed to align the risk level with the risk appetite.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 49: ''Residual risk is the risk that remains after risk treatment.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 43: ''Risk appetite is the amount of risk, on a broad level, that an entity is willing to accept in pursuit of value.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 50: ''The information security manager should compare the residual risk with the risk appetite and determine whether the risk treatment options are sufficient, excessive, or inadequate.''

asked 01/10/2024
Yedron Rojas Acosta
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first