nerdexam
Isaca

CISM · Question #708

A new privacy regulation includes significant financial penalties for breaches. Which of the following would BEST enable the information security manager to gain a better understanding of the impact…

The correct answer is C. Business impact analysis (BIA). A Business Impact Analysis (BIA) is the right tool here because it directly quantifies the potential consequences - financial, operational, and reputational - that a specific threat (in this case, regulatory non-compliance penalties) could have on the organization, which is…

Submitted by andreas_gr· Apr 18, 2026Information Security Risk Management

Question

A new privacy regulation includes significant financial penalties for breaches. Which of the following would BEST enable the information security manager to gain a better understanding of the impact this regulation may have on the organization?

Options

  • AQualitative risk assessment
  • BCost-benefit assessment
  • CBusiness impact analysis (BIA)
  • DControl gap assessment

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    74% (26)
  • D
    11% (4)

Explanation

A Business Impact Analysis (BIA) is the right tool here because it directly quantifies the potential consequences - financial, operational, and reputational - that a specific threat (in this case, regulatory non-compliance penalties) could have on the organization, which is exactly what the manager needs to understand.

Why the distractors fall short:

  • A (Qualitative risk assessment) evaluates likelihood and severity using descriptive scales (high/medium/low), but doesn't provide the concrete financial impact data needed when real dollar penalties are involved.
  • B (Cost-benefit assessment) compares costs of controls against benefits - useful for justifying a solution, but you can't do that until you first understand the impact the regulation poses.
  • D (Control gap assessment) identifies where existing controls fall short against a standard - useful for remediation planning, but it tells you what's missing, not what the business stands to lose.

Memory tip: Think of BIA as answering "how bad could it get?" - it's always the starting point when the concern is impact to the organization. If the question mentions financial penalties, downtime costs, or operational disruption, BIA is almost always the answer before any other assessment can be meaningful.

Topics

#Business Impact Analysis#Regulatory Compliance#Risk Assessment#Impact Assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice