nerdexam
Isaca

CISM · Question #869

Which of the following should occur FIRST in the process of managing security risk associated with the transfer of data from unsupported legacy systems to supported systems?

The correct answer is D. Identity all information assets in the legacy environment. You must first identify all information assets in the legacy environment so the organization knows what data exists, where it resides, and what needs protection during transfer; this inventory is the foundation for assigning ownership, performing a BIA, and planning/testing…

Submitted by skyler.x· Apr 18, 2026Information Security Risk Management

Question

Which of the following should occur FIRST in the process of managing security risk associated with the transfer of data from unsupported legacy systems to supported systems?

Options

  • AAssign owners to be responsible for the transfer of each asset.
  • BConduct a business impact analysis (BIA).
  • CPerform security testing on legacy systems.
  • DIdentity all information assets in the legacy environment.

How the community answered

(29 responses)
  • A
    10% (3)
  • C
    3% (1)
  • D
    86% (25)

Explanation

You must first identify all information assets in the legacy environment so the organization knows what data exists, where it resides, and what needs protection during transfer; this inventory is the foundation for assigning ownership, performing a BIA, and planning/testing secure migration

Topics

#Risk Management Process#Asset Identification#Data Security#Legacy Systems

Community Discussion

No community discussion yet for this question.

Full CISM Practice