Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 837 discussion

Actual exam question from Isaca's CISM
Question #: 837
Topic #: 1
[All CISM Questions]

Which of the following BEST enables an information security manager to obtain organizational support for the implementation of security controls?

  • A. Conducting periodic vulnerability assessments
  • B. Defining the organization's risk management framework
  • C. Communicating business impact analysis (BIA) results
  • D. Establishing effective stakeholder relationships
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Yahealborini
1 month, 3 weeks ago
Selected Answer: D
Proper answer is D
upvoted 1 times
...
Raj91188
1 month, 4 weeks ago
Selected Answer: C
BIA results provide a factual, measurable understanding of the potential consequences of security failures, which directly connects security controls to business continuity. Stakeholders are often more inclined to support initiatives when they see how they affect the bottom line, productivity, or risk to the organization. Quantifiable Impact: Communicating the BIA results turns abstract security concepts into tangible risks and consequences, making the case for security controls more persuasive, especially when addressing business-focused stakeholders. Alignment with Business Objectives: By linking security efforts to business impact, this approach ensures that decisions are aligned with overall strategic goals, reducing resistance that might come from purely technical justifications.
upvoted 1 times
...
Thavee
7 months ago
Selected Answer: C
I think business impact talks louder here. Not sure what kind of relationship is that. Party together at night?
upvoted 1 times
...
Salilgen
8 months ago
Selected Answer: D
BIA is useful to assign priority actions in recovery plans.
upvoted 1 times
...
Marcelus1714
9 months, 1 week ago
Selected Answer: D
it says "support for the IMPLEMENTATION", so if you don't have good relationships is an important problem
upvoted 1 times
...
Bl1024
9 months, 2 weeks ago
Selected Answer: C
Why not C? Good relationships are something that will always benefit a goal but thinking that security is dependant on good relationships as the "best" path, is a scary thought.
upvoted 1 times
...
richck102
1 year, 4 months ago
D. Establishing effective stakeholder relationships
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: D
Establishing effective stakeholder relationships is crucial for obtaining organizational support for the implementation of security controls. Building positive relationships with stakeholders across different departments and levels of the organization helps foster understanding, trust, and collaboration. It allows the information security manager to effectively communicate the importance of security controls and gain support for their implementation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...