nerdexam
Isaca

CISM · Question #771

Which of the following tasks would provide a newly appointed information security manager with the BEST view of the organization's existing security posture?

The correct answer is B. Performing a risk assessment. Performing a risk assessment (B) gives the most comprehensive, structured view of an organization's security posture because it systematically identifies assets, threats, vulnerabilities, and existing controls - producing a measurable, prioritized picture of where the…

Submitted by haruto_sh· Apr 18, 2026Information Security Risk Management

Question

Which of the following tasks would provide a newly appointed information security manager with the BEST view of the organization's existing security posture?

Options

  • AReviewing policies and procedures
  • BPerforming a risk assessment
  • CInterviewing business managers and employees
  • DPerforming a business impact analysis (BIA)

How the community answered

(48 responses)
  • A
    23% (11)
  • B
    58% (28)
  • C
    6% (3)
  • D
    13% (6)

Explanation

Performing a risk assessment (B) gives the most comprehensive, structured view of an organization's security posture because it systematically identifies assets, threats, vulnerabilities, and existing controls - producing a measurable, prioritized picture of where the organization stands against risk. Reviewing policies and procedures (A) only reveals what the organization intends to do, not what is actually practiced or how effective controls are. Interviewing business managers and employees (C) provides qualitative insight but is inconsistent and lacks the systematic coverage needed for a complete posture assessment. A BIA (D) focuses on operational impact and recovery priorities for critical processes, which is useful for continuity planning but does not assess the breadth of security controls and vulnerabilities.

Memory tip: Think of a risk assessment as a "security X-ray" - it sees everything at once (assets, threats, gaps, controls), while the other options are like looking through individual windows. When a question asks for the best overall view, the answer is almost always the option that is systematic and comprehensive.

Topics

#Risk assessment#Security posture#Information security management#Initial assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice