CISSP · Question #1000
An organization is setting a security assessment scope with the goal of developing a Security Management Program (SMP). The next step is to select an approach for conducting the risk assessment…
The correct answer is C. Business processes based risk assessment with a focus on business goals. When developing a Security Management Program (SMP), the business processes based risk assessment approach is the most effective because it ties security directly to the organization's business goals and critical processes. This ensures that security efforts are aligned with…
Question
Options
- AData driven risk assessment with a focus on data
- BSecurity controls driven assessment that focuses on controls management
- CBusiness processes based risk assessment with a focus on business goals
- DAsset driven risk assessment with a focus on the assets
How the community answered
(43 responses)- A9% (4)
- B2% (1)
- C84% (36)
- D5% (2)
Explanation
When developing a Security Management Program (SMP), the business processes based risk assessment approach is the most effective because it ties security directly to the organization's business goals and critical processes. This ensures that security efforts are aligned with the overall objectives of the organization and are designed to protect the processes that are vital to the business. This approach helps in understanding and mitigating risks that could impact business operations, revenue, reputation, and compliance with legal or regulatory requirements. Focusing on business processes allows the risk assessment to identify the key assets, people, and activities that drive the organization's mission. It ensures that the security controls implemented are both effective and aligned with what truly matters to the business.
Topics
Community Discussion
No community discussion yet for this question.