CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 30


What should be an information security manager's FIRST step when developing a business case for a new intrusion detection system (IDS) solution?

Show Answer
Correct Answer: BC

When developing a business case for a new intrusion detection system (IDS) solution, the first step should be to define the issues to be addressed. Clearly identifying and articulating the specific security challenges and problems that the IDS solution aims to solve provides a foundation for the entire business case. This step ensures that subsequent analyses, like cost-benefit analysis or feasibility studies, are grounded in the actual needs and objectives of the organization.

Discussion

17 comments
Sign in to comment
JKatta2023Option: C
Jun 23, 2023

B and C are very close. If you don't have issues, why would you look to address them. When you start to address, you do cost benefit analysis to see if it is worth spending the amount to solve the issues. I would like to know why C is the answer.

ManixOption: C
Oct 20, 2023

Implementing IDS imply that issues are already known. So it's C.

Learner76Option: B
Nov 8, 2023

I am leaning towards B but the answer is C and I think it is because 1) It is a business case - Cost 2) IDS was mentioned. Meaning the technology are already chosen because they know what is the issue Therefore it is a cost benefit stage. Therefore C

ViperhunterOption: B
Nov 20, 2023

Before delving into financial calculations or feasibility studies, it's crucial to clearly identify and define the issues or challenges that the organization is seeking to address with the new IDS solution. Understanding the specific security needs and concerns provides a foundation for developing a comprehensive business case. This step helps in articulating the objectives, benefits, and requirements associated with the proposed solution. While calculating the total cost of ownership (TCO) (option A), performing a cost-benefit analysis (option C), and conducting a feasibility study (option D) are important components of the business case development process, defining the issues to be addressed is the initial step that sets the direction for the rest of the analysis.

shervin2sOption: B
Mar 5, 2024

Before delving into financial considerations such as calculating the total cost of ownership (TCO), performing a cost-benefit analysis, or conducting a feasibility study, it's crucial to clearly define the issues that the intrusion detection system (IDS) solution is intended to address.

richck102Option: B
May 14, 2023

B. Define the issues to be addressed.

Patt70Option: B
Jun 26, 2023

Answer is B - I agree with Broesweelies's comment.

Azurefox79Option: B
Aug 8, 2023

Cant perform a CBA is you dont know what is being addressed.

RidenarOption: B
Aug 8, 2023

B know what problems you are trying to solve

AgamennoreOption: B
Aug 29, 2023

It’B. First step define the objective and know what to do

Jess20Option: B
Nov 10, 2023

B. Define the issues to be addressed. Most Voted

POWNEDOption: B
Nov 21, 2023

1. Clearly define the problem 2. Follow an order 3. Possible benefits and reason 4. The final results

peeluOption: B
Dec 10, 2023

Define the issues or challenges

Bankie_72Option: C
Jan 1, 2024

C is the correct answer because anytime a business case is being developed, cost benefit analysis is a key component of its development, irrespective of what the business case is used for and especially when dealing with senior stakeholders.

Marcelus1714
Feb 18, 2024

It says "the FIRST" thing, not the most important. If you do not have clear what issues you gonna address... how you can do a cost-benefit analysis...??

oluchecpointOption: B
Feb 2, 2024

Option B

GrantolioOption: B
Mar 2, 2024

The text book says the first this is describing the problem. Sounds like B. From the CISM Exam Guide, Second Edition, P. Gregory, pg 89: Developing a Business Case Many organizations require the development of a business case prior to approving expenditures on significant security initiatives. A business case is a written statement that describes the initiative and describes its business benefits.<...> The typical elements found in a business case include the following: • Problem statement This is a description of the business condition or situation that the initiative is designed to solve. The condition may be a matter of compliance, a finding in a risk assessment, or a capability required by a customer, partner, supplier, or regulator.

usercism007Option: B
Jun 19, 2024

Selected Answer: B The first step is "Define the issues to be addressed." when developing a business case for a new intrusion detection system (IDS) solution