nerdexam
GIAC

GSEC · Question #88

Which of the below choices should an organization start with when implementing an effective risk management process?

The correct answer is B. Define security policy requirements. An effective risk management program must begin with defining security policy requirements, as policy establishes the governance framework that drives all subsequent decisions.

Incident Handling, Risk, and Governance

Question

Which of the below choices should an organization start with when implementing an effective risk management process?

Options

  • AImplement an incident response plan
  • BDefine security policy requirements
  • CConduct periodic reviews
  • DDesign controls and develop standards for each technology you plan to deploy

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    73% (27)
  • C
    14% (5)
  • D
    8% (3)

Why each option

An effective risk management program must begin with defining security policy requirements, as policy establishes the governance framework that drives all subsequent decisions.

AImplement an incident response plan

An incident response plan is a reactive component of risk management and can only be meaningfully designed after policies define what assets and risks require protection.

BDefine security policy requirementsCorrect

Security policies define the organization's risk tolerance, objectives, and compliance obligations, providing the foundational framework from which all other risk management activities are derived. Without established policy, there is no authoritative basis for selecting controls, defining standards, or conducting meaningful reviews, making it the essential first step.

CConduct periodic reviews

Periodic reviews are an ongoing, cyclical activity intended to assess the effectiveness of controls already in place and cannot be the starting point of a program.

DDesign controls and develop standards for each technology you plan to deploy

Designing controls and technology standards presupposes that policies exist to specify what must be protected and to what degree, so controls must follow policy, not precede it.

Concept tested: Risk management process initiation with security policy

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk management#security policy#governance#risk framework

Community Discussion

No community discussion yet for this question.

Full GSEC Practice