exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1203 discussion

Actual exam question from Isaca's CISM
Question #: 1203
Topic #: 1
[All CISM Questions]

When considering a new security initiative, which of the following should be done prior to the development of a business case?

  • A. Conduct a risk assessment
  • B. Conduct a benchmarking exercise
  • C. Perform a cost-benefit analysis
  • D. Identify resource requirements
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SHERLOCKAWS
4 days, 8 hours ago
Selected Answer: A
Answer is A: Because it provides the evidence and context needed to build a solid, risk-aligned business case for any new security initiative. cost benefit analysis is in the business case.
upvoted 1 times
...
Pichon
2 weeks, 2 days ago
Selected Answer: A
1 step is a risk assessment; then on the business case, you need to do a risk cost analysis after you analyze the risks.
upvoted 1 times
...
PluDou_111
4 weeks, 1 day ago
Selected Answer: A
RA, The correct answer is: A. Conduct a risk assessment Explanation: Before developing a business case for a new security initiative, a risk assessment should be conducted to identify potential threats, vulnerabilities, and the impact on the organization. This helps in determining whether the initiative is necessary and aligns with the organization’s risk management strategy. • B. Conduct a benchmarking exercise – This can provide useful insights but is typically done after understanding the organization’s specific risks. • C. Perform a cost-benefit analysis – This is part of the business case development and comes after identifying risks and determining the need for the initiative. • D. Identify resource requirements – This is a later step after establishing the justification for the initiative. By conducting a risk assessment first, the organization ensures that the security initiative is driven by actual business and security needs rather than assumptions.
upvoted 1 times
...
Josef4CISM
2 months, 1 week ago
Selected Answer: C
My take is: A security initiative is the result of a risk assessment. E.g., the security initiative could mean the implementation of a SIEM as a mitigating control. Therefore, a risk assessment is given already. To decide whether certain controls should be implemented, a cost-benefit analysis must be done. If costs outweigh benefits, there is no need to write a business case. If benefits outweigh costs, the cost-benefit analysis will be part of the business case later on.
upvoted 3 times
...
ServerBrain
5 months, 1 week ago
Selected Answer: A
A. Conduct a risk assessment
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago