CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 1027


Which of the following defines the MOST comprehensive set of security requirements for a newly developed information system?

Show Answer
Correct Answer: C

A risk assessment systematically identifies, analyzes, and evaluates potential risks impacting an information system. It informs the development of a comprehensive set of security requirements tailored to the specific risks faced by the system. This ensures that both existing and additional necessary security controls are addressed, making it the most thorough approach compared to predefined baseline controls, audit findings, or key risk indicators.

Discussion

10 comments
Sign in to comment
Cyberbug2021Option: A
Nov 23, 2023

Baseline controls represent the most comprehensive set of security requirements for a newly developed information system. These controls provide a foundation of security measures that should be implemented regardless of the specific risks or vulnerabilities of the system. They cover a wide range of security aspects, including access control, data protection, network security, and application security.

richck102Option: C
Nov 20, 2023

C. Risk assessment results

Uncle_LuciferOption: C
Dec 6, 2023

Risk assessment first, before developing Baseline controls. You cannot apply controls blindly without knowing what needs it

SoleandheelOption: C
Nov 27, 2023

C. Risk assessment results is more comprehensive than A. Baseline controls

koala_layOption: C
Dec 12, 2023

The most comprehensive set of security requirements for a newly developed information system would be defined by C. Risk assessment results. Risk assessment is a systematic process of identifying, analyzing, and evaluating potential risks to determine the effectiveness of existing security controls and identify any additional security requirements that may be necessary. By analyzing the results of a risk assessment, one can determine the specific security measures and controls needed to protect the information system effectively.

POWNEDOption: C
Feb 1, 2024

The answer is C, key here is provide a foundation.

POWNED
Feb 1, 2024

Sorry I meant to say A.

FantasyDreamOption: A
Feb 7, 2024

If risks are accepted without any need for additional controls, then the risk assessment itself doesn't result in new requirements. Baseline controls are a set of standard security requirements that apply to all systems within an organization to provide a minimum level of security.

xcjxcj
Mar 15, 2024

Baseline is minimum = least COMPREHENSIVE C is comprehensive

3czzOption: A
Feb 23, 2024

I would go with A

yottabyteOption: A
Mar 18, 2024

I would go with A stating baseline requirements for a newly developed information system as they don't require to be part of the system however analysis from the risk assessment results would be involved in the selection of baseline controls.

1899f17Option: C
May 28, 2024

C. Risk assessment results