AAISM · Question #138
An organization plans to leverage AI in the software development process to speed up coding. Which of the following should the information security manager do FIRST?
The correct answer is A. Conduct an impact assessment. An impact assessment must come first because it establishes the risk baseline - identifying what data the AI tool accesses, what vulnerabilities it introduces, regulatory implications, and organizational readiness. All subsequent actions depend on this analysis. Training…
Question
An organization plans to leverage AI in the software development process to speed up coding. Which of the following should the information security manager do FIRST?
Options
- AConduct an impact assessment
- BTrain developers to verify AI output
- CUpdate the security policy to include AI controls
- DPerform a cost-benefit analysis
How the community answered
(21 responses)- A81% (17)
- B5% (1)
- C5% (1)
- D10% (2)
Explanation
An impact assessment must come first because it establishes the risk baseline - identifying what data the AI tool accesses, what vulnerabilities it introduces, regulatory implications, and organizational readiness. All subsequent actions depend on this analysis. Training developers (B) and updating policy (C) are informed by what the impact assessment reveals. A cost-benefit analysis (D) is a business decision that also relies on understanding the security and operational impact. Acting without an impact assessment means implementing controls blindly, which violates fundamental risk management principles.
Topics
Community Discussion
No community discussion yet for this question.