nerdexam
Isaca

AAISM · Question #138

An organization plans to leverage AI in the software development process to speed up coding. Which of the following should the information security manager do FIRST?

The correct answer is A. Conduct an impact assessment. An impact assessment must come first because it establishes the risk baseline - identifying what data the AI tool accesses, what vulnerabilities it introduces, regulatory implications, and organizational readiness. All subsequent actions depend on this analysis. Training…

AI Security Risk Management

Question

An organization plans to leverage AI in the software development process to speed up coding. Which of the following should the information security manager do FIRST?

Options

  • AConduct an impact assessment
  • BTrain developers to verify AI output
  • CUpdate the security policy to include AI controls
  • DPerform a cost-benefit analysis

How the community answered

(21 responses)
  • A
    81% (17)
  • B
    5% (1)
  • C
    5% (1)
  • D
    10% (2)

Explanation

An impact assessment must come first because it establishes the risk baseline - identifying what data the AI tool accesses, what vulnerabilities it introduces, regulatory implications, and organizational readiness. All subsequent actions depend on this analysis. Training developers (B) and updating policy (C) are informed by what the impact assessment reveals. A cost-benefit analysis (D) is a business decision that also relies on understanding the security and operational impact. Acting without an impact assessment means implementing controls blindly, which violates fundamental risk management principles.

Topics

#AI Risk Management#Impact Assessment#Security Planning#SDLC Security

Community Discussion

No community discussion yet for this question.

Full AAISM Practice