CISM · Question #13
When building support for an information security program, which of the following elements is MOST important?
The correct answer is D. Information risk assessment. Building support for an information security program is most effectively achieved by demonstrating the specific risks the program addresses through a comprehensive risk assessment.
Question
When building support for an information security program, which of the following elements is MOST important?
Options
- ABusiness impact analysis (BIA)
- BIdentification of existing vulnerabilities
- CThreat analysis
- DInformation risk assessment
How the community answered
(64 responses)- A6% (4)
- B14% (9)
- C3% (2)
- D77% (49)
Why each option
Building support for an information security program is most effectively achieved by demonstrating the specific risks the program addresses through a comprehensive risk assessment.
A Business Impact Analysis (BIA) focuses on the impact of business disruptions and aids in recovery planning, but it does not specifically identify the security risks an information security program aims to mitigate.
Identification of existing vulnerabilities is a component of a risk assessment, but it lacks the broader context of potential threats, impact, and likelihood required to build a full justification for an entire program.
Threat analysis identifies potential adversaries and their methods, but without assessing vulnerabilities and the business impact, it does not provide a complete picture for justifying a security program.
An information risk assessment identifies, analyzes, and evaluates potential security threats and vulnerabilities, quantifying the potential impact on the business. This process clearly articulates the 'why' behind security investments, making it the most important element for gaining management support by linking security directly to business impact.
Concept tested: Justifying security programs through risk management
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.