nerdexam
Isaca

CISM · Question #209

When analyzing the emerging risk and threat landscape, an information security manager should FIRST:

The correct answer is B. map threats to business assets. Mapping threats to business assets must come first because it establishes the foundational context for all subsequent risk analysis. Without knowing which assets exist and which threats are relevant to them, you cannot meaningfully assess impact (D), prioritize threat sources…

Submitted by jordan8· Apr 18, 2026Information Security Risk Management

Question

When analyzing the emerging risk and threat landscape, an information security manager should FIRST:

Options

  • Adetermine the sources of emerging threats.
  • Bmap threats to business assets.
  • Creview historical threats within the industry.
  • Ddetermine the impact if threats materialize.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    80% (16)
  • C
    5% (1)
  • D
    10% (2)

Explanation

Mapping threats to business assets must come first because it establishes the foundational context for all subsequent risk analysis. Without knowing which assets exist and which threats are relevant to them, you cannot meaningfully assess impact (D), prioritize threat sources (A), or contextualize historical data (C). The asset-threat mapping defines the scope and relevance of the entire threat landscape analysis - it answers 'what are we actually protecting and from what?' before any deeper analysis begins.

Topics

#Threat Analysis#Risk Assessment#Asset Identification#Emerging Risks

Community Discussion

No community discussion yet for this question.

Full CISM Practice