ExamGecko
Question list
Search
Search

Question 623 - CISM discussion

Report
Export

Which of the following is MOST appropriate to communicate to senior management regarding information risk?

A.
Emerging security technologies
Answers
A.
Emerging security technologies
B.
Risk profile changes
Answers
B.
Risk profile changes
C.
Defined risk appetite
Answers
C.
Defined risk appetite
D.
Vulnerability scanning progress
Answers
D.
Vulnerability scanning progress
Suggested answer: B

Explanation:

Risk profile changes are the most appropriate to communicate to senior management regarding information risk because they reflect the current level and nature of the risks that the organization faces and how they may affect its objectives and performance. Senior management needs to be aware of any changes in the risk profile so that they can make informed decisions and allocate resources accordingly. Risk profile changes also help senior management monitor the effectiveness of the risk management process and identify any gaps or weaknesses that need to be addressed.

Reference=Communicating Information Security Risk Simply and Effectively, Part 1,CISM Domain 2: Information Risk Management (IRM) [2022 update]

asked 01/10/2024
Mark Singer
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first