ExamGecko
Question list
Search
Search

Question 628 - CISM discussion

Report
Export

Which of the following is the PRIMARY responsibility of the information security function when an organization adopts emerging technologies?

A.
Developing security training for the new technologies
Answers
A.
Developing security training for the new technologies
B.
Designing new security controls
Answers
B.
Designing new security controls
C.
Creating an acceptable use policy for the technologies
Answers
C.
Creating an acceptable use policy for the technologies
D.
Assessing the potential security risk
Answers
D.
Assessing the potential security risk
Suggested answer: D

Explanation:

The primary responsibility of the information security function when an organization adopts emerging technologies is to assess the potential security risk, which means identifying and evaluating the threats, vulnerabilities, and impacts that the new technologies may pose to the organization's data, systems, and objectives. Assessing the potential security risk helps the information security function to determine the appropriate security requirements, controls, and measures to mitigate the risk and ensure the safe and secure adoption of the emerging technologies.

Reference=Performing Risk Assessments of Emerging Technologies,CISM Review Manual 15th Edition

Learn more:

1. isaca.org2. isaca.org3. niccs.cisa.gov4. venturebeat.com

10of30

An organization is planning to outsource network management to a service provider. Including which of the following in the contract would be the MOST effective way to mitigate information security risk? A. Requirement for regular information security awareness B. Right-to-audit clause C. Service level agreement (SLA) D. Requirement to comply with corporate security policy Answer: (Refer to

asked 01/10/2024
Ciaran Cullimore
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first