Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 47 discussion

Actual exam question from Isaca's CISM
Question #: 47
Topic #: 1
[All CISM Questions]

When designing security controls, it is MOST important to:

  • A. focus on preventive controls.
  • B. apply controls to confidential information.
  • C. evaluate the costs associated with the controls.
  • D. apply a risk-based approach.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
greeklover84
1 month, 4 weeks ago
Selected Answer: D
D makes more sense since this is the MOST important to start sorting the issues considering the risk and then start checking the cost of the mitigation control vs the impact.
upvoted 1 times
...
alifjouj
2 months, 3 weeks ago
Selected Answer: D
controls are designed to mitigate risks.
upvoted 2 times
...
Viperhunter
12 months ago
Selected Answer: D
Applying a risk-based approach involves identifying and assessing the risks faced by the organization and then designing security controls that are proportionate to the identified risks. This ensures that resources are allocated efficiently and that security measures are aligned with the organization's risk tolerance and priorities. While focusing on preventive controls (option A) is important, an exclusive focus on prevention may not adequately address all potential risks. Applying controls to confidential information (option B) is essential but should be guided by the overall risk landscape. Evaluating the costs associated with controls (option C) is also important, but cost-effectiveness should be considered in the context of risk reduction. A risk-based approach helps organizations prioritize and tailor their security controls to address the most significant threats and vulnerabilities.
upvoted 3 times
...
Nickprata
1 year ago
Selected Answer: C
You can suggest 10M solution to save 1M company. So cost is important factor for designing a control.
upvoted 2 times
...
Perseus_68
1 year, 1 month ago
You apply a risk-based approach for the asset with the control in mind. This question is for the control only, C is then the correct answer.
upvoted 2 times
...
AaronS1990
1 year, 2 months ago
Selected Answer: D
D definitely. C is also important but as an ISM your job is all about considering risk.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
D While preventive controls (option A) are important, they are only one aspect of a comprehensive security strategy. Focusing solely on preventive controls without considering the organization's specific risks may result in inefficient resource allocation and an inadequate response to the most critical threats. Applying controls to confidential information (option B) is also important but should be guided by the overall risk assessment and not solely based on confidentiality. Different types of information may have varying levels of sensitivity, and a risk-based approach helps determine appropriate controls for each. In summary, applying a risk-based approach to security control design ensures that an organization's security measures are tailored to its unique risk profile, leading to more effective and efficient security.
upvoted 1 times
...
Azurefox79
1 year, 3 months ago
Selected Answer: C
C. This is where experience comes in. Anyone who designs controls without cost in mind will know they will immediately be rejected by Senior Management. Its a waste of time if you dont consider cost. Also, this is a Business Mindset exam, not a sec analyst exam. Cost is everything for the CISM.
upvoted 2 times
CISSPST
1 year, 2 months ago
Value creation (one of the primary objectives of Governance) is realizing benefits at an optimal resource cost while optimizing risk.......So, no, cost is not everything. Cost if just one side of the coin.
upvoted 2 times
...
...
JKatta2023
1 year, 4 months ago
If you don't know the risk, how would you calculate the cost vs benefit. I would think D is a better option than C. Interested to hear why is C a better answer than D?
upvoted 1 times
Azurefox79
1 year, 3 months ago
Its C. its not asking about cost vs benefit. Just cost. I ALWAYS have to have cost in mind in designing controls. Otherwise, I design awesome controls and I get rejected for budget because they are more expensive than the assets they protect. If you dont get cost right, nothing else will matter because you wont get any money. This is business mindset exam, not a Security + exam.
upvoted 2 times
...
...
karanvp
1 year, 5 months ago
Answer C Think about small organisation which dont have much capital to invest, but has high potential risk for it's business vector. This kind of organisation looking for cost effective compensation controls instead of implementing expensive security controls. Hence top most priority is cost on selecting the controls.
upvoted 1 times
[Removed]
1 year, 5 months ago
cost effectiveness is based on the risk . FIrst you have to do risk assesment, then decide cost of controls
upvoted 1 times
...
...
richck102
1 year, 6 months ago
D. apply a risk-based approach.
upvoted 1 times
...
Seasondream
1 year, 6 months ago
Selected Answer: D
D. Apply a risk-based approach is the MOST important when designing security controls. This means identifying and prioritizing risks, assessing the likelihood and impact of potential threats, and selecting controls that are appropriate and cost-effective to mitigate those risks. A risk-based approach ensures that security controls are tailored to the specific needs of the organization and aligned with its business objectives. While preventive controls are important, they may not be sufficient to address all security risks. It is also important to consider detective and corrective controls to detect and respond to security incidents. Confidential information may require more stringent controls, but all information assets should be assessed for risk and addressed accordingly. Finally, the costs associated with the controls should be evaluated, but this should not be the only consideration, as the cost of a security breach can be much higher.
upvoted 2 times
...
hardyheron
1 year, 8 months ago
The correct answer is D. Risk reduction is the primary objective of any control implementation.
upvoted 1 times
...
cangurer
1 year, 8 months ago
D is correct. Cost of the control is important but you should consider the value of protected data as well.
upvoted 1 times
...
CarlLimps
1 year, 9 months ago
Selected Answer: D
Folks. The answer is D. Repeat after me..."Take a risk-based approach". All other options are part of taking an RBA. Always take a risk based approach when identifying controls. Did I mention...take a risk based approach when identifying controls? :)
upvoted 2 times
...
STUDYER2
1 year, 9 months ago
Selected Answer: B
Agree to be B
upvoted 1 times
...
Antonivs
1 year, 9 months ago
Selected Answer: C
C & D are ok
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...