CISM · Question #209
When analyzing the emerging risk and threat landscape, an information security manager should FIRST:
The correct answer is B. map threats to business assets. Mapping threats to business assets must come first because it establishes the foundational context for all subsequent risk analysis. Without knowing which assets exist and which threats are relevant to them, you cannot meaningfully assess impact (D), prioritize threat sources…
Question
When analyzing the emerging risk and threat landscape, an information security manager should FIRST:
Options
- Adetermine the sources of emerging threats.
- Bmap threats to business assets.
- Creview historical threats within the industry.
- Ddetermine the impact if threats materialize.
How the community answered
(20 responses)- A5% (1)
- B80% (16)
- C5% (1)
- D10% (2)
Explanation
Mapping threats to business assets must come first because it establishes the foundational context for all subsequent risk analysis. Without knowing which assets exist and which threats are relevant to them, you cannot meaningfully assess impact (D), prioritize threat sources (A), or contextualize historical data (C). The asset-threat mapping defines the scope and relevance of the entire threat landscape analysis - it answers 'what are we actually protecting and from what?' before any deeper analysis begins.
Topics
Community Discussion
No community discussion yet for this question.