nerdexam
Isaca

CGEIT · Question #8

A large retail chain realizes that while there has not been any loss of da a, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high…

The correct answer is A. Identifying gaps in information asset protection. To make IT security a priority, the first high-level initiative for an IT strategy committee should be to identify existing gaps in information asset protection.

Submitted by chen.hong· Apr 18, 2026Risk Optimization

Question

A large retail chain realizes that while there has not been any loss of da a, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high- level initiative for a newly created IT strategy committee in order to support this business goal?

Options

  • AIdentifying gaps in information asset protection
  • BDefining data archiving and retrieval policies
  • CRecruiting and training qualified IT security staff
  • DModernizing internal IT security practices

How the community answered

(53 responses)
  • A
    83% (44)
  • B
    2% (1)
  • C
    6% (3)
  • D
    9% (5)

Why each option

To make IT security a priority, the first high-level initiative for an IT strategy committee should be to identify existing gaps in information asset protection.

AIdentifying gaps in information asset protectionCorrect

Before any specific improvements or investments can be made, the IT strategy committee must first understand the current state of information asset protection to identify weaknesses, vulnerabilities, and areas lacking adequate controls. This assessment provides the necessary baseline to formulate an effective IT security strategy and prioritize subsequent initiatives.

BDefining data archiving and retrieval policies

Defining data archiving and retrieval policies is a specific operational task that comes after understanding the overall security posture and needs.

CRecruiting and training qualified IT security staff

Recruiting and training staff is an important resource management aspect but should be informed by the identified security gaps and strategic needs.

DModernizing internal IT security practices

Modernizing practices is a broad improvement initiative that requires prior knowledge of *what* needs modernization, which comes from gap identification.

Concept tested: Initial step in IT security strategy

Topics

#IT Security Strategy#Risk Assessment#Information Asset Protection#Strategic Initiative

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice