nerdexam
Isaca

CISM · Question #223

Which of the following would BEST ensure that security risk assessment is integrated into the life cycle of major IT projects?

The correct answer is B. Having the information security manager participate on the project steering committees. The best way to ensure that security risk assessment is integrated into the life cycle of major IT projects is by having the information security manager participate on the project steering committees. This ensures that security risks are consistently considered and addressed dur

Submitted by obi.ng· Apr 18, 2026Information Security Governance

Question

Which of the following would BEST ensure that security risk assessment is integrated into the life cycle of major IT projects?

Options

  • AIntegrating the risk assessment into the internal audit program
  • BHaving the information security manager participate on the project steering committees
  • CApplying global security standards to the IT projects
  • DTraining project managers on risk assessment

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    70% (16)
  • C
    13% (3)
  • D
    13% (3)

Explanation

The best way to ensure that security risk assessment is integrated into the life cycle of major IT projects is by having the information security manager participate on the project steering committees. This ensures that security risks are consistently considered and addressed during key project phases and decision-making. While training project managers and applying global standards are helpful, direct involvement by the information security manager in steering committees allows for ongoing oversight and integration of security risk assessments throughout the project's life cycle.

Topics

#Security Risk Assessment#Project Life Cycle Integration#Information Security Governance#Steering Committee

Community Discussion

No community discussion yet for this question.

Full CISM Practice