CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 1


An information security risk analysis BEST assists an organization in ensuring that:

Show Answer
Correct Answer: B

An information security risk analysis helps an organization make cost-effective decisions regarding which assets need protection by identifying and prioritizing potential risks. This process involves assessing the likelihood and impact of various threats and determining which assets are most critical and require appropriate security measures based on the level of risk they pose. Hence, it ensures that resources are allocated efficiently to safeguard the most important assets.

Discussion

14 comments
Sign in to comment
MSKidOption: B
Sep 19, 2022

CISM - AIO 2nd - The risk analyst studies different event scenarios and determines the impact of each. This may be expressed in quantitative terms (dollars or other currency) or qualitative terms (high/medium/low or a numeric scale of 1 to 5 or of 1 to 10). Sounds like B to me

Ziggybooboo
Sep 21, 2022

Agreed

ViperhunterOption: B
Nov 20, 2023

Information security risk analysis helps organizations identify and prioritize potential risks to their information assets. By assessing the likelihood and impact of various risks, organizations can make informed and cost-effective decisions about where to allocate resources for protection. This involves determining which assets are most critical and require heightened security measures based on the level of risk they pose. While the other options (ensuring appropriate access control, applying appropriate funding to security processes, and implementing appropriate security technologies) are also important considerations, the primary benefit of risk analysis is in facilitating cost-effective decisions related to asset protection.

PrasannacpwOption: B
Nov 30, 2022

agreed

anshutiOption: B
Jan 24, 2023

Helps define level of protection

richck102Option: B
May 10, 2023

B - cost-effective decisions are made with regard to which assets need protection

peelu
Jun 4, 2023

Information security risk analysis helps to define level of protection.

peeluOption: B
Jun 4, 2023

Information security risk analysis helps to define level of protection.

puggalhimanyaOption: B
Aug 10, 2023

Asset protection as per the data stored in it is HIGHEST priority while doing Risk Analysis

Ali29Option: B
Sep 26, 2023

B. cost-effective decisions are made with regard to which assets need protection

CISSPSTOption: B
Dec 22, 2023

Will go with the explanation by Viperhunter

GambleJaiOption: D
Jan 2, 2024

CRISC indicated that when new compliance regulation might affect the business, it should first analyse the existing control enough to meet the regulation of new compliance rule. Clearly the answer is D

Shay91
May 17, 2024

Are these answers valid for the actual exam?

fodaja6399Option: A
Jul 4, 2024

(A is correct) if you want valid Questions and Answers. You have the site name above.

Mojo__Option: B
Jul 15, 2024

B is correct answers exam still valid, took it today and all thanks ExamforSure.com