nerdexam
EC-Council

712-50 · Question #445

A CISO must conduct risk assessments using a method where the Chief Financial Officer (CFO) receives impact data in financial terms to use as input to select the proper level of coverage in a new cybe

The correct answer is A. Conduct a quantitative risk assessment. Quantitative risk assessment assigns monetary values to potential cybersecurity risks based on their impact and likelihood. This method translates risk into objective financial terms that CFOs can understand and use for decision-making, including choosing an appropriate level of

IS Management Controls and Auditing Management

Question

A CISO must conduct risk assessments using a method where the Chief Financial Officer (CFO) receives impact data in financial terms to use as input to select the proper level of coverage in a new cybersecurity insurance policy. What is the MOST effective method of risk analysis to provide the CFO with the information required?

Options

  • AConduct a quantitative risk assessment
  • BConduct a hybrid risk assessment
  • CConduct a subjective risk assessment
  • DConduct a qualitative risk assessment

How the community answered

(49 responses)
  • A
    78% (38)
  • B
    6% (3)
  • C
    12% (6)
  • D
    4% (2)

Explanation

Quantitative risk assessment assigns monetary values to potential cybersecurity risks based on their impact and likelihood. This method translates risk into objective financial terms that CFOs can understand and use for decision-making, including choosing an appropriate level of insurance coverage. It provides clear cost-benefit analysis for risk mitigation investments and risk transfer decisions, aligning well with financial planning needs.

Topics

#quantitative risk assessment#financial impact#risk analysis#cyber insurance

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice