ExamGecko
Question list
Search
Search

Question 634 - CISM discussion

Report
Export

An organization implemented a number of technical and administrative controls to mitigate risk associated with ransomware. Which of the following is MOST important to present to senior management when reporting on the performance of this initiative?

A.
The total cost of the investment
Answers
A.
The total cost of the investment
B.
The cost and associated risk reduction
Answers
B.
The cost and associated risk reduction
C.
The number and severity of ransomware incidents
Answers
C.
The number and severity of ransomware incidents
D.
Benchmarks of industry peers impacted by ransomware
Answers
D.
Benchmarks of industry peers impacted by ransomware
Suggested answer: B

Explanation:

The most important information to present to senior management when reporting on the performance of the initiative to mitigate risk associated with ransomware is the cost and associated risk reduction, which means showing the value and effectiveness of the technical and administrative controls in terms of reducing the likelihood and impact of ransomware incidents and data extortion, and comparing them with the investment and resources required to implement and maintain them. The cost and associated risk reduction can help senior management to evaluate the return on investment (ROI) and the alignment with the business objectives and risk appetite of the initiative.

Reference=Ransomware Risk Management - NIST,#StopRansomware Guide | CISA

asked 01/10/2024
Kevin Brigitta
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first