B.
This approach helps in making informed decisions about which security controls to implement, prioritizing them based on their alignment with business goals, and justifying the allocation of resources to security activities in a way that makes sense for the organization as a whole.
Going to have to go with A for this one and this is why. Lots of the CISM questions revolve around stakeholders and costs. B seems like a throw off answer for test takers that do not know what they are talking about, never have I ever seen "ensure that benefits are aligned with business strategies" when talking about a cost benefit analysis, and this is coming from someone who has the Project+ certification. Again this test leans heavily on stakeholders and cost keep this in mind for future questions.
B.
This approach helps in making informed decisions about which security controls to implement, prioritizing them based on their alignment with business goals, and justifying the allocation of resources to security activities in a way that makes sense for the organization as a whole.
Performing a cost-benefit analysis helps to determine whether the cost of implementing a security control is justified by the benefits that it provides. By analyzing the potential costs and benefits of a control, an organization can ensure that the mitigation effort does not exceed the value of the asset being protected. This allows for a more efficient use of resources and helps to prioritize the implementation of security controls based on their expected impact.
Answer B: The MOST important reason for performing a cost-benefit analysis when implementing a security control is to ensure that benefits are aligned with business strategies. By conducting a cost-benefit analysis, the information security manager can evaluate the potential benefits of a security control against the costs of implementation and maintenance. This enables the manager to identify controls that provide the best return on investment and align with the organization's overall business strategies. It also helps in prioritizing security controls and making informed decisions about which security measures to implement.
Fr... It's literally A, says directly in ISACA's review manual.....
"A cost-benefit analysis should be performed to justify the investment in controls to mitigate risks. Controls should not be more costly than the impact of the risk event's consequences if it occurs. The cost of implementing and maintaining controls (mitigation) should not exceed the value of the asset at risk."
Dudes have no idea how bad chatgpt can be with tight questions, especially ones based specifically on specific editions, not just "In general".
Answer B: The MOST important reason for performing a cost-benefit analysis when implementing a security control is to ensure that benefits are aligned with business strategies. By conducting a cost-benefit analysis, the information security manager can evaluate the potential benefits of a security control against the costs of implementation and maintenance. This enables the manager to identify controls that provide the best return on investment and align with the organization's overall business strategies. It also helps in prioritizing security controls and making informed decisions about which security measures to implement.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
david124
1 week, 4 days agousercism007
5 months, 3 weeks agooluchecpoint
9 months, 2 weeks agoPOWNED
11 months, 4 weeks agomarcelus
1 year, 1 month agooluchecpoint
1 year, 2 months agoGoseu
1 year, 3 months agojjj378
1 year, 5 months agorichck102
1 year, 5 months agoAbhey
1 year, 6 months agojcmu11
1 year, 7 months ago[Removed]
1 year, 4 months ago[Removed]
1 year, 3 months agoseric01
8 months, 2 weeks agojcmu11
1 year, 7 months ago