ExamGecko
Question list
Search
Search

Question 615 - CISM discussion

Report
Export

Which of the following would be of GREATEST assistance in determining whether to accept residual risk of a critical security system?

A.
Available annual budget
Answers
A.
Available annual budget
B.
Cost-benefit analysis of mitigating controls
Answers
B.
Cost-benefit analysis of mitigating controls
C.
Recovery time objective (RTO)
Answers
C.
Recovery time objective (RTO)
D.
Maximum tolerable outage (MTO)
Answers
D.
Maximum tolerable outage (MTO)
Suggested answer: B

Explanation:

Cost-benefit analysis of mitigating controls is the BEST way to assist in determining whether to accept residual risk of a critical security system, because it helps to compare the costs of implementing and maintaining the controls with the benefits of reducing the risk and the potential losses. Cost-benefit analysis can help to justify the investment in security controls and to optimize the level of residual risk that is acceptable for the organization.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 50: ''Cost-benefit analysis is the process of comparing the costs of risk treatment options with the benefits of risk reduction and the potential losses from risk events.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 51: ''Cost-benefit analysis can help to justify the investment in information security controls and to optimize the level of residual risk that is acceptable for the enterprise.''

CISM Domain 2: Information Risk Management (IRM) [2022 update]: ''Cost-benefit analysis: This is a comparison of the costs of implementing and maintaining security controls with the benefits of reducing risk and potential losses. It helps to justify the investment in security controls and optimize the level of residual risk.''

asked 01/10/2024
Steven Chong
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first