ExamGecko
Question list
Search
Search

Question 614 - CISM discussion

Report
Export

When developing an information security strategy for an organization, which of the following is MOST helpful for understanding where to focus efforts?

A.
Gap analysis
Answers
A.
Gap analysis
B.
Project plans
Answers
B.
Project plans
C.
Vulnerability assessment
Answers
C.
Vulnerability assessment
D.
Business impact analysis (BIA)
Answers
D.
Business impact analysis (BIA)
Suggested answer: A

Explanation:

Gap analysis is the MOST helpful tool for understanding where to focus efforts when developing an information security strategy for an organization, because it helps to identify the current state and the desired state of the information security governance, and the gaps between them. Gap analysis also helps to prioritize the actions and resources needed to close the gaps and achieve the information security objectives.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: ''Gap analysis is the process of comparing the current state and the desired state of information security governance and identifying the gaps that need to be addressed.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 37: ''Gap analysis should be performed periodically to assess the effectiveness and efficiency of the information security strategy and program and to identify the areas for improvement.''

CISM domain 1: Information security governance [Updated 2022] - Infosec Resources: ''Gap analysis: This is a comparison of the current state of security with the desired state. It helps to identify the gaps in security and prioritize the actions required to close them.''

asked 01/10/2024
Ankit Parimi
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first