nerdexam
Isaca

CISM · Question #388

Which of the following is an information security manager's BEST course of action when a business unit manager wants to adopt an emerging technology that may affect the organization?

The correct answer is C. Conduct a threat analysis. When an emerging technology is being considered for adoption, a threat analysis is the most appropriate first step because it identifies the specific threats that the new technology could introduce or be susceptible to, allowing the security manager to understand the risk…

Submitted by mike_84· Apr 18, 2026Information Security Risk Management

Question

Which of the following is an information security manager's BEST course of action when a business unit manager wants to adopt an emerging technology that may affect the organization?

Options

  • APerform a vulnerability assessment.
  • BReview the vendor documentation.
  • CConduct a threat analysis.
  • DPerform a business impact analysis (BIA).

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    13% (3)
  • C
    75% (18)
  • D
    4% (1)

Explanation

When an emerging technology is being considered for adoption, a threat analysis is the most appropriate first step because it identifies the specific threats that the new technology could introduce or be susceptible to, allowing the security manager to understand the risk landscape before a decision is made. A vulnerability assessment (A) is better suited to technology already deployed, where specific technical weaknesses can be tested. Reviewing vendor documentation (B) provides useful context but is not a formal security analysis. A business impact analysis (D) assesses the effect of disruptions on business functions and is not designed to evaluate threats introduced by new technology adoption.

Topics

#Emerging Technology Risk#Threat Analysis#Risk Identification#Information Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice