CGEIT · Question #257
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
The correct answer is D. Integrate IT risk assessment into the overall due diligence process. The best approach for reviewing the security status of a new business acquisition is to integrate IT risk assessment directly into the pre-acquisition due diligence process.
Question
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
Options
- AEmbed IT risk management strategies in service level agreements (SLAs).
- BEstablish a committee to oversee the alignment of IT security in new businesses.
- CIncorporate IT security objectives to cover additional risks associated with new businesses.
- DIntegrate IT risk assessment into the overall due diligence process.
How the community answered
(27 responses)- A4% (1)
- B4% (1)
- C11% (3)
- D81% (22)
Why each option
The best approach for reviewing the security status of a new business acquisition is to integrate IT risk assessment directly into the pre-acquisition due diligence process.
Embedding IT risk management in SLAs is a post-acquisition operational step for managing service providers, not the best approach for initially reviewing the security status of an acquisition.
Establishing a committee is a governance structure for ongoing oversight, but it typically comes after the initial security review during the acquisition phase.
Incorporating IT security objectives is a planning step for the post-acquisition environment, but it relies on an initial assessment to understand the specific risks, which is performed during due diligence.
Integrating IT risk assessment into the overall due diligence process is the best approach because it allows for a comprehensive evaluation of the acquired company's security posture, vulnerabilities, and potential risks before the acquisition is finalized. This proactive step informs the acquisition decision and facilitates effective post-acquisition integration planning.
Concept tested: M&A IT security due diligence
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-benchmark-v3-governance-strategy#gs-3-incorporate-security-in-mergers-and-acquisitions
Topics
Community Discussion
No community discussion yet for this question.