If the residual risk has already been calculated and confirmed to have increased, the business impact should have already been considered as part of that calculation. In this case, reassessing the business impact might not be necessary because it was already factored into the residual risk analysis.
CISM QA are not consistent. Some went to management first, but some action by ISM is taken first. What about the assessment comes with cost and time?? Why dont we just go to senior management first, telling them about the story. Later on, ask the Senior management for budget/time/OT/Resources to do the assessment. Assessments may not be done in just half an hour like patching the windows, but it may need all departments to get involved.
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Jess20
Highly Voted 1 year, 5 months ago841c750
Most Recent 5 months, 1 week agoc041644
1 year agoThavee
1 year agoAaronS1990
1 year, 8 months agosphenixfire
1 year, 10 months ago[Removed]
1 year, 10 months agorichck102
1 year, 11 months ago