CISM · Question #978
What should an information security manager verify FIRST when reviewing an information asset management program?
The correct answer is D. Information assets have been inventoried.. Inventorying information assets (D) must happen first because you cannot manage, classify, secure, or assign ownership to assets you don't know exist - an inventory is the foundational step that makes all other activities possible. Why the distractors are wrong: A (securing key a
Question
What should an information security manager verify FIRST when reviewing an information asset management program?
Options
- AKey applications have been secured.
- BSystem owners have been identified.
- CInformation assets have been classified.
- DInformation assets have been inventoried.
How the community answered
(24 responses)- A4% (1)
- C8% (2)
- D88% (21)
Explanation
Inventorying information assets (D) must happen first because you cannot manage, classify, secure, or assign ownership to assets you don't know exist - an inventory is the foundational step that makes all other activities possible.
Why the distractors are wrong:
- A (securing key applications) - Security controls come much later in the lifecycle; you can't secure what you haven't catalogued and classified yet.
- B (identifying system owners) - Ownership assignment is important, but it's a step that occurs after assets are discovered and listed in the inventory.
- C (classifying information assets) - Classification is the natural second step after inventorying; you categorize what you've already found, not the other way around.
Memory tip: Think of it as building a house - you need to lay the foundation (inventory) before you can put up walls (classification), install locks (security controls), or hand out keys (assign owners). The sequence is: Inventory → Classify → Own → Secure.
Topics
Community Discussion
No community discussion yet for this question.