Isaca
CISM · Question #533
During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:
The correct answer is D. perform a risk assessment.. During due diligence, conducting a risk assessment is key to uncovering the target’s security exposures, quantifying their potential impact, and informing both go/no-go decisions and negotiation of remediation or pricing.
Submitted by kwame.gh· Apr 18, 2026Information Security Risk Management
Question
During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:
Options
- Areview information security policies.
- Breview the state of security awareness.
- Cperform a gap analysis.
- Dperform a risk assessment.
How the community answered
(34 responses)- A21% (7)
- B6% (2)
- C3% (1)
- D71% (24)
Explanation
During due diligence, conducting a risk assessment is key to uncovering the target’s security exposures, quantifying their potential impact, and informing both go/no-go decisions and negotiation of remediation or pricing.
Topics
#Due diligence#Acquisition security#Risk assessment#M&A security
Community Discussion
No community discussion yet for this question.