ExamGecko
Question list
Search
Search

Question 664 - CISM discussion

Report
Export

Which of the following BEST indicates the organizational benefit of an information security solution?

A.
Cost savings the solution brings to the information security department
Answers
A.
Cost savings the solution brings to the information security department
B.
Reduced security training requirements
Answers
B.
Reduced security training requirements
C.
Alignment to security threats and risks
Answers
C.
Alignment to security threats and risks
D.
Costs and benefits of the solution calculated over time
Answers
D.
Costs and benefits of the solution calculated over time
Suggested answer: D

Explanation:

The best option to indicate the organizational benefit of an information security solution is D. Costs and benefits of the solution calculated over time. This is because costs and benefits of the solution calculated over time, also known as the return on security investment (ROSI), can help to measure and demonstrate the value and effectiveness of the information security solution in terms of reducing risks, enhancing performance, and achieving strategic goals. ROSI can also help to justify the allocation and optimization of the resources and budget for the information security solution, and to compare and prioritize different security alternatives. ROSI can be calculated by using various methods and formulas, such as the annualized loss expectancy (ALE), the annualized rate of occurrence (ARO), and the cost-benefit analysis (CBA).

Costs and benefits of the solution calculated over time, also known as the return on security investment (ROSI), can help to measure and demonstrate the value and effectiveness of the information security solution in terms of reducing risks, enhancing performance, and achieving strategic goals. (From CISM Manual or related resources)

Reference = CISM Review Manual 15th Edition, Chapter 3, Section 3.1.3, page 1311; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 99, page 26; How to Calculate Return on Security Investment (ROSI) - Infosec2

asked 01/10/2024
Arno Rodenhuis
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first