nerdexam
(ISC)2

CISSP · Question #1000

An organization is setting a security assessment scope with the goal of developing a Security Management Program (SMP). The next step is to select an approach for conducting the risk assessment…

The correct answer is C. Business processes based risk assessment with a focus on business goals. When developing a Security Management Program (SMP), the business processes based risk assessment approach is the most effective because it ties security directly to the organization's business goals and critical processes. This ensures that security efforts are aligned with…

Submitted by daniela_cl· Mar 5, 2026Security and Risk Management

Question

An organization is setting a security assessment scope with the goal of developing a Security Management Program (SMP). The next step is to select an approach for conducting the risk assessment. Which of the following approaches is MOST effective for the SMP?

Options

  • AData driven risk assessment with a focus on data
  • BSecurity controls driven assessment that focuses on controls management
  • CBusiness processes based risk assessment with a focus on business goals
  • DAsset driven risk assessment with a focus on the assets

How the community answered

(43 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    84% (36)
  • D
    5% (2)

Explanation

When developing a Security Management Program (SMP), the business processes based risk assessment approach is the most effective because it ties security directly to the organization's business goals and critical processes. This ensures that security efforts are aligned with the overall objectives of the organization and are designed to protect the processes that are vital to the business. This approach helps in understanding and mitigating risks that could impact business operations, revenue, reputation, and compliance with legal or regulatory requirements. Focusing on business processes allows the risk assessment to identify the key assets, people, and activities that drive the organization's mission. It ensures that the security controls implemented are both effective and aligned with what truly matters to the business.

Topics

#risk assessment#security management program#business processes

Community Discussion

No community discussion yet for this question.

Full CISSP Practice