nerdexam
Isaca

CGEIT · Question #490

Which of the following is the BEST way to address the risk associated with new IT investments?

The correct answer is B. Integrate security requirements at the beginning of projects. The best way to address risks with new IT investments is to integrate security requirements at the beginning of projects, fostering a secure-by-design approach.

Submitted by fernanda_arg· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the BEST way to address the risk associated with new IT investments?

Options

  • ADevelop security best practices to protect applications.
  • BIntegrate security requirements at the beginning of projects
  • CEstablish an enterprise-wide incident response process.
  • DImplement an enterprise-wide security awareness program.

How the community answered

(43 responses)
  • A
    9% (4)
  • B
    67% (29)
  • C
    19% (8)
  • D
    5% (2)

Why each option

The best way to address risks with new IT investments is to integrate security requirements at the beginning of projects, fostering a secure-by-design approach.

ADevelop security best practices to protect applications.

Developing security best practices is important but represents general guidelines; integrating specific security requirements into new projects from the start is more proactive and directly addresses the unique risks of those investments.

BIntegrate security requirements at the beginning of projectsCorrect

Integrating security requirements at the beginning of projects, often referred to as 'security by design' or 'shift-left' security, is the most effective approach as it ensures security is built into the architecture and processes from the outset. This proactive measure is far more cost-effective and robust than attempting to add security controls after development is complete.

CEstablish an enterprise-wide incident response process.

Establishing an incident response process is crucial for reacting to security incidents, but it is a reactive measure rather than a proactive one for mitigating risks associated with new investments during their development.

DImplement an enterprise-wide security awareness program.

Implementing a security awareness program helps educate users, but while important, it does not directly address the technical risks inherent in the design and implementation of new IT investments as effectively as integrating security requirements into the project lifecycle.

Concept tested: Proactive security risk management

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/security-by-design

Topics

#IT Governance#IT Risk Management#Security by Design#Project Lifecycle

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice