Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1027 discussion

Actual exam question from Isaca's CISM
Question #: 1027
Topic #: 1
[All CISM Questions]

Which of the following defines the MOST comprehensive set of security requirements for a newly developed information system?

  • A. Baseline controls
  • B. Audit findings
  • C. Risk assessment results
  • D. Key risk indicators (KRIs)
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
4 months ago
A - Baseline controls represent the foundational security requirements that an organization establishes for its systems. These controls cover essential security aspects and serve as a starting point for securing the system. They include fundamental practices such as access controls, encryption, patch management, and configuration standards. C, is however, they focus on identifying and prioritizing risks rather than specifying detailed security requirements.
upvoted 1 times
...
1899f17
5 months, 3 weeks ago
C. Risk assessment results
upvoted 1 times
...
yottabyte
8 months, 1 week ago
Selected Answer: A
I would go with A stating baseline requirements for a newly developed information system as they don't require to be part of the system however analysis from the risk assessment results would be involved in the selection of baseline controls.
upvoted 2 times
...
3czz
9 months ago
Selected Answer: A
I would go with A
upvoted 1 times
...
FantasyDream
9 months, 2 weeks ago
Selected Answer: A
If risks are accepted without any need for additional controls, then the risk assessment itself doesn't result in new requirements. Baseline controls are a set of standard security requirements that apply to all systems within an organization to provide a minimum level of security.
upvoted 1 times
xcjxcj
8 months, 1 week ago
Baseline is minimum = least COMPREHENSIVE C is comprehensive
upvoted 1 times
...
...
POWNED
9 months, 3 weeks ago
Selected Answer: C
The answer is C, key here is provide a foundation.
upvoted 1 times
POWNED
9 months, 3 weeks ago
Sorry I meant to say A.
upvoted 1 times
...
...
koala_lay
11 months, 1 week ago
Selected Answer: C
The most comprehensive set of security requirements for a newly developed information system would be defined by C. Risk assessment results. Risk assessment is a systematic process of identifying, analyzing, and evaluating potential risks to determine the effectiveness of existing security controls and identify any additional security requirements that may be necessary. By analyzing the results of a risk assessment, one can determine the specific security measures and controls needed to protect the information system effectively.
upvoted 1 times
...
Uncle_Lucifer
11 months, 2 weeks ago
Selected Answer: C
Risk assessment first, before developing Baseline controls. You cannot apply controls blindly without knowing what needs it
upvoted 2 times
...
Soleandheel
11 months, 4 weeks ago
C. Risk assessment results is more comprehensive than A. Baseline controls
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: A
Baseline controls represent the most comprehensive set of security requirements for a newly developed information system. These controls provide a foundation of security measures that should be implemented regardless of the specific risks or vulnerabilities of the system. They cover a wide range of security aspects, including access control, data protection, network security, and application security.
upvoted 3 times
...
richck102
1 year ago
Selected Answer: C
C. Risk assessment results
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...