nerdexam
Isaca

CISM · Question #817

An organization is in the process of acquiring a competitor. The information security manager has been asked to report on the security posture of the target acquisition. Which of the following…

The correct answer is A. Perform a security assessment. To report on the security posture of a target acquisition, the first step is to perform a security assessment. This provides a factual, risk-based understanding of existing controls, vulnerabilities, and gaps, which is essential before benchmarking, threat profiling, or…

Submitted by lukas.cz· Apr 18, 2026Information Security Risk Management

Question

An organization is in the process of acquiring a competitor. The information security manager has been asked to report on the security posture of the target acquisition. Which of the following should be the security manager's FIRST course of action?

Options

  • APerform a security assessment.
  • BImplement a security dashboard.
  • CPerform a benchmark analysis.
  • DCreate a threat profile.

How the community answered

(58 responses)
  • A
    79% (46)
  • B
    12% (7)
  • C
    3% (2)
  • D
    5% (3)

Explanation

To report on the security posture of a target acquisition, the first step is to perform a security assessment. This provides a factual, risk-based understanding of existing controls, vulnerabilities, and gaps, which is essential before benchmarking, threat profiling, or reporting through

Topics

#Security Assessment#Mergers and Acquisitions#Due Diligence#Risk Identification

Community Discussion

No community discussion yet for this question.

Full CISM Practice