CISM · Question #388
Which of the following is an information security manager's BEST course of action when a business unit manager wants to adopt an emerging technology that may affect the organization?
The correct answer is C. Conduct a threat analysis. When an emerging technology is being considered for adoption, a threat analysis is the most appropriate first step because it identifies the specific threats that the new technology could introduce or be susceptible to, allowing the security manager to understand the risk…
Question
Which of the following is an information security manager's BEST course of action when a business unit manager wants to adopt an emerging technology that may affect the organization?
Options
- APerform a vulnerability assessment.
- BReview the vendor documentation.
- CConduct a threat analysis.
- DPerform a business impact analysis (BIA).
How the community answered
(24 responses)- A8% (2)
- B13% (3)
- C75% (18)
- D4% (1)
Explanation
When an emerging technology is being considered for adoption, a threat analysis is the most appropriate first step because it identifies the specific threats that the new technology could introduce or be susceptible to, allowing the security manager to understand the risk landscape before a decision is made. A vulnerability assessment (A) is better suited to technology already deployed, where specific technical weaknesses can be tested. Reviewing vendor documentation (B) provides useful context but is not a formal security analysis. A business impact analysis (D) assesses the effect of disruptions on business functions and is not designed to evaluate threats introduced by new technology adoption.
Topics
Community Discussion
No community discussion yet for this question.