nerdexam
Isaca

CGEIT · Question #257

Which of the following is the BEST approach when reviewing The security status of a new business acquisition?

The correct answer is D. Integrate IT risk assessment into the overall due diligence process. The best approach for reviewing the security status of a new business acquisition is to integrate IT risk assessment directly into the pre-acquisition due diligence process.

Submitted by rohit_dlh· Apr 18, 2026Risk Optimization

Question

Which of the following is the BEST approach when reviewing The security status of a new business acquisition?

Options

  • AEmbed IT risk management strategies in service level agreements (SLAs).
  • BEstablish a committee to oversee the alignment of IT security in new businesses.
  • CIncorporate IT security objectives to cover additional risks associated with new businesses.
  • DIntegrate IT risk assessment into the overall due diligence process.

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    11% (3)
  • D
    81% (22)

Why each option

The best approach for reviewing the security status of a new business acquisition is to integrate IT risk assessment directly into the pre-acquisition due diligence process.

AEmbed IT risk management strategies in service level agreements (SLAs).

Embedding IT risk management in SLAs is a post-acquisition operational step for managing service providers, not the best approach for initially reviewing the security status of an acquisition.

BEstablish a committee to oversee the alignment of IT security in new businesses.

Establishing a committee is a governance structure for ongoing oversight, but it typically comes after the initial security review during the acquisition phase.

CIncorporate IT security objectives to cover additional risks associated with new businesses.

Incorporating IT security objectives is a planning step for the post-acquisition environment, but it relies on an initial assessment to understand the specific risks, which is performed during due diligence.

DIntegrate IT risk assessment into the overall due diligence process.Correct

Integrating IT risk assessment into the overall due diligence process is the best approach because it allows for a comprehensive evaluation of the acquired company's security posture, vulnerabilities, and potential risks before the acquisition is finalized. This proactive step informs the acquisition decision and facilitates effective post-acquisition integration planning.

Concept tested: M&A IT security due diligence

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-benchmark-v3-governance-strategy#gs-3-incorporate-security-in-mergers-and-acquisitions

Topics

#M&A Security#Due Diligence (IT)#IT Risk Assessment#Acquisition Strategy

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice