nerdexam
Isaca

CISM · Question #510

An information security manager's cost estimate for a multi-component identity and access management (IAM) initiative is too expensive and complex for a single implementation. What is the BEST way…

The correct answer is D. Rate them according to reduction in residual risk. When a security initiative must be phased due to cost and complexity, components should be prioritized by the degree to which they reduce residual risk. This approach ensures the organization gets the greatest risk reduction per dollar spent, which is the core objective of any…

Submitted by kev92· Apr 18, 2026Information Security Risk Management

Question

An information security manager's cost estimate for a multi-component identity and access management (IAM) initiative is too expensive and complex for a single implementation. What is the BEST way to prioritize the components?

Options

  • ARate them according to financial benefit.
  • BRate them according to cost of implementation.
  • CRate them according to ease of implementation.
  • DRate them according to reduction in residual risk.

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    8% (2)
  • C
    4% (1)
  • D
    76% (19)

Explanation

When a security initiative must be phased due to cost and complexity, components should be prioritized by the degree to which they reduce residual risk. This approach ensures the organization gets the greatest risk reduction per dollar spent, which is the core objective of any security investment. Rating by financial benefit (A) is too broad. Prioritizing by cost (B) or ease (C) optimizes for convenience rather than security value and may leave the most critical risks unaddressed longest.

Topics

#Prioritization#Risk Management#IAM#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice