CISM · Question #150
When developing a business case for a new security initiative, an information security manager should FIRST:
The correct answer is D. define the issues to be addressed. Defining the issues to be addressed is the necessary first step because every subsequent element of a business case - feasibility, cost, benefit - depends on a clear problem statement. Without knowing what problem you are solving, you cannot assess feasibility (A), calculate…
Question
When developing a business case for a new security initiative, an information security manager should FIRST:
Options
- Aconduct a feasibility study.
- Bcalculate the total cost of ownership (TCO).
- Cperform a cost-benefit analysis.
- Ddefine the issues to be addressed.
How the community answered
(27 responses)- A4% (1)
- C4% (1)
- D93% (25)
Explanation
Defining the issues to be addressed is the necessary first step because every subsequent element of a business case - feasibility, cost, benefit - depends on a clear problem statement. Without knowing what problem you are solving, you cannot assess feasibility (A), calculate relevant costs (B), or perform a meaningful cost-benefit analysis (C). A well-defined problem statement also ensures alignment with business objectives and makes the case more compelling to stakeholders. This follows the fundamental principle: understand the problem before proposing a solution.
Topics
Community Discussion
No community discussion yet for this question.