nerdexam
Isaca

CISM · Question #536

Which of the following should be an information security manager's PRIMARY focus when preparing for the rollout of a bring your own device (BYOD) program?

The correct answer is B. Performing a risk assessment. Performing a risk assessment identifies the specific threats, vulnerabilities, and impact associated with BYOD, establishing the foundation for appropriate policies, controls, and technology choices to mitigate those risks.

Submitted by devops_kid· Apr 18, 2026Information Security Risk Management

Question

Which of the following should be an information security manager's PRIMARY focus when preparing for the rollout of a bring your own device (BYOD) program?

Options

  • ASelecting a mobile device management (MDM) solution
  • BPerforming a risk assessment
  • CBenchmarking BYOD incidents within the industry
  • DDocumenting BYOD policy and procedures

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    78% (40)
  • C
    12% (6)
  • D
    6% (3)

Explanation

Performing a risk assessment identifies the specific threats, vulnerabilities, and impact associated with BYOD, establishing the foundation for appropriate policies, controls, and technology choices to mitigate those risks.

Topics

#BYOD#Risk Assessment#Program Planning#Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice