CISM · Question #510
An information security manager's cost estimate for a multi-component identity and access management (IAM) initiative is too expensive and complex for a single implementation. What is the BEST way…
The correct answer is D. Rate them according to reduction in residual risk. When a security initiative must be phased due to cost and complexity, components should be prioritized by the degree to which they reduce residual risk. This approach ensures the organization gets the greatest risk reduction per dollar spent, which is the core objective of any…
Question
An information security manager's cost estimate for a multi-component identity and access management (IAM) initiative is too expensive and complex for a single implementation. What is the BEST way to prioritize the components?
Options
- ARate them according to financial benefit.
- BRate them according to cost of implementation.
- CRate them according to ease of implementation.
- DRate them according to reduction in residual risk.
How the community answered
(25 responses)- A12% (3)
- B8% (2)
- C4% (1)
- D76% (19)
Explanation
When a security initiative must be phased due to cost and complexity, components should be prioritized by the degree to which they reduce residual risk. This approach ensures the organization gets the greatest risk reduction per dollar spent, which is the core objective of any security investment. Rating by financial benefit (A) is too broad. Prioritizing by cost (B) or ease (C) optimizes for convenience rather than security value and may leave the most critical risks unaddressed longest.
Topics
Community Discussion
No community discussion yet for this question.