CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 676


An organization is going through a digital transformation process, which places the IT organization in an unfamiliar risk landscape. The information security manager has been tasked with leading the IT risk management process. Which of the following should be given the HIGHEST priority?

Show Answer
Correct Answer: A

In the context of IT risk management during a digital transformation process, the highest priority should be the identification of risks. Without identifying the risks, it is impossible to analyze control gaps, select appropriate risk treatment options, or design effective key risk indicators (KRIs). Identifying risks is the foundation of any risk management process and must be addressed first to ensure that subsequent steps are based on an accurate understanding of the potential threats and vulnerabilities.

Discussion

9 comments
Sign in to comment
MyKasalaOption: A
Jan 24, 2023

A is correct

oluchecpointOption: C
Sep 9, 2023

This is the highest priority because it involves evaluating the existing controls and processes in place to mitigate risks associated with digital transformation. By assessing control gaps, you can determine where vulnerabilities or weaknesses exist, which is critical for making informed decisions about risk treatment options (Option B) and designing effective KRIs (Option D).

aokisanOption: C
Dec 24, 2022

at first, evaluate gap.

Michi23
Jan 16, 2023

How do you know about existing risk when you dont identify them? After Identification you can evaluate the gap.

RowlandmarcOption: C
Jul 4, 2023

at first, evaluate gap.

richck102Option: A
Jul 7, 2023

A. Identification of risk

wickhaarryOption: C
Jul 26, 2023

HIGHEST priority? C

Marcelus1714Option: A
Feb 3, 2024

come on! HIGHEST priority is to identify the risks! then you can do your gap analysis...

xcjxcjOption: C
Mar 11, 2024

C is most important. A is first, C is prioritized. You cannot prioritise appetizers over main course.

03allenOption: A
Jun 26, 2024

controls are based on the risks.