nerdexam
Isaca

CISM · Question #13

When building support for an information security program, which of the following elements is MOST important?

The correct answer is D. Information risk assessment. Building support for an information security program is most effectively achieved by demonstrating the specific risks the program addresses through a comprehensive risk assessment.

Submitted by asante_acc· Apr 18, 2026Information Risk Management

Question

When building support for an information security program, which of the following elements is MOST important?

Options

  • ABusiness impact analysis (BIA)
  • BIdentification of existing vulnerabilities
  • CThreat analysis
  • DInformation risk assessment

How the community answered

(64 responses)
  • A
    6% (4)
  • B
    14% (9)
  • C
    3% (2)
  • D
    77% (49)

Why each option

Building support for an information security program is most effectively achieved by demonstrating the specific risks the program addresses through a comprehensive risk assessment.

ABusiness impact analysis (BIA)

A Business Impact Analysis (BIA) focuses on the impact of business disruptions and aids in recovery planning, but it does not specifically identify the security risks an information security program aims to mitigate.

BIdentification of existing vulnerabilities

Identification of existing vulnerabilities is a component of a risk assessment, but it lacks the broader context of potential threats, impact, and likelihood required to build a full justification for an entire program.

CThreat analysis

Threat analysis identifies potential adversaries and their methods, but without assessing vulnerabilities and the business impact, it does not provide a complete picture for justifying a security program.

DInformation risk assessmentCorrect

An information risk assessment identifies, analyzes, and evaluates potential security threats and vulnerabilities, quantifying the potential impact on the business. This process clearly articulates the 'why' behind security investments, making it the most important element for gaining management support by linking security directly to business impact.

Concept tested: Justifying security programs through risk management

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Information Risk Assessment#Program Justification#Stakeholder Buy-in#Information Security Program Development

Community Discussion

No community discussion yet for this question.

Full CISM Practice