CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 29


Deciding the level of protection a particular asset should be given is BEST determined by:

Show Answer
Correct Answer: B

Deciding the level of protection a particular asset should be given is best determined by a risk analysis. A risk analysis evaluates the potential threats, vulnerabilities, and impacts associated with an asset to determine the level of risk it poses. By considering the likelihood and potential consequences of various risks, an organization can make informed decisions about the appropriate level of protection needed. This approach ensures a comprehensive evaluation of all relevant factors, providing a clear basis for determining the necessary safeguards.

Discussion

17 comments
Sign in to comment
CISSPSTOption: A
Dec 26, 2023

Risk analysis gives the level of risk, not level of protection. After a risk analysis, the business then evaluates the level of (inherent/existing) risk against acceptable risk levels (RISK APETITE) to decide the level of protection to be provided, in a manner that the residual risk is within acceptable risk levels.

AWSgenioOption: B
Feb 27, 2024

At 1st i thought A. After re-reading the question, which "should" be given vs "will" be given. "Should be given" will be determined by Risk Analysis. "Will be given" will be risk appetite. So B for me.

BamBamBigalo
Jun 12, 2024

Thats a good exam tip, thank you

RidenarOption: B
Aug 8, 2023

B key words deciding and determined

Cyberbug2021Option: B
Nov 21, 2023

While the corporate risk appetite reflects the organization's overall tolerance for risk, it doesn't directly address the specific risks associated with individual assets. A risk analysis is necessary to assess the risks specific to each asset.

AlexJacobsonOption: A
Dec 1, 2023

I think it's A. Risk analysis is a process that tells you the amount of risk affecting an asset. But ultimately the risk appetite of the business will determine how much money goes into managing the risk (mitigating it, transferring, etc.). Because you can point out the amount of risk, but if the management says "nah, it'll be fine" (to quote The Critical Drinker here :D) that is what's gonna dictate how much is gonna be invested in protecting a particular asset.

shervin2sOption: A
Mar 5, 2024

Conducting a risk analysis allows for a comprehensive evaluation of the threats, vulnerabilities, and potential impacts associated with specific assets. By analyzing these factors, organizations can make informed decisions about the level of protection required for each asset. Explanation of why other options are not correct: A. The corporate risk appetite: While the corporate risk appetite influences overall risk management decisions, including the allocation of resources and the establishment of risk tolerance levels, it does not directly determine the level of protection for individual assets. Risk appetite provides a high-level framework for decision-making but must be translated into specific risk analysis for each asset.

Cert_ITOption: B
Sep 19, 2023

a comprehensive risk analysis takes into account all relevant factors, including threats, vulnerabilities, asset value, and risk appetite, to determine the appropriate level of protection for a particular asset.

Learner76Option: B
Nov 8, 2023

B, because risk level is achieved by doing analysis. Not A, risk appetite is subjective.

POWNEDOption: B
Nov 9, 2023

Look at risk appetite like a policy, and risk analysis like control objectives. Your going to need to analyze the risk (control objectives) in order to ensure the risk appetite (policy) is met. Best answer here is B

ViperhunterOption: B
Nov 20, 2023

A risk analysis involves evaluating the potential threats, vulnerabilities, and impacts associated with an asset to determine the level of risk it poses. By considering the likelihood and potential consequences of various risks, organizations can make informed decisions about the appropriate level of protection needed for specific assets. This process takes into account the organization's risk tolerance, business objectives, and overall risk management strategy. While the corporate risk appetite (option A), threat assessments (option C), and vulnerability assessments (option D) are important components of the risk analysis process, conducting a comprehensive risk analysis provides a holistic view that considers all relevant factors in determining the appropriate level of protection for an asset.

MSKidOption: B
Dec 7, 2023

Answer is B: for a particular asset, risk analysis.

Uncle_LuciferOption: A
Dec 7, 2023

Majority are wrong. Should be risk appetite

TamerBeSafeOption: B
Dec 10, 2023

The Corporate Risk Appetite: it is a broad guideline and does not provide specific details on the level of protection for individual assets.

oluchecpointOption: A
Feb 2, 2024

Risk appetite

yottabyteOption: B
Mar 12, 2024

Risk analysis can be performed to determine the level of protection required to be provided to an asset.

ThaveeOption: A
Mar 24, 2024

Risk appetite

RagazzoAlexOption: B
Jul 17, 2024

The question is asking a bout a specific asset and specific here is a key work. risk appetite is more generic