D. Align with the risk appetite is the information security manager's best approach when selecting cost-effective controls needed to meet business objectives.
The risk appetite is the level of risk that an organization is willing to accept in order to achieve its objectives. It is a key consideration when selecting controls, as it determines how much the organization is willing to invest in security.
A security manager should align the controls with the risk appetite by considering the potential impact of a security incident on the organization and the likelihood of it occurring. This approach allows the security manager to select cost-effective controls that are appropriate for the organization's specific needs and budget, while also ensuring that the organization's assets and operations are protected. This approach also allows the organization to prioritize the most critical risks and allocate resources accordingly, ensuring that the most important risks are addressed first.
Risk appetite - Company at different maturity level have different risk appetite and have different view on spending. E.g Startup could be more risk adverse and willing to take more risk therefore spend less on security
you got it wrong, The page is not referring to COST-effective controls.
The answer to this question is page 104, "Risk assessment....s used as a basis for identifying appropriate and cost-effective controls " And then is mentioning the 4 areas that make up Risk Posture ( Risk Identification, Analysis, Evaluation etc.
D
By aligning with the risk appetite, an information security manager ensures that the security controls implemented are in line with the organization's overall risk tolerance. This approach allows for a balanced and cost-effective selection of controls that are neither overly restrictive nor insufficient for the organization's needs.
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Broesweelies
Highly Voted 1 year, 9 months agoLearner76
Most Recent 11 months agowickhaarry
1 year, 1 month agocidigi
6 months, 3 weeks agooluchecpoint
1 year, 1 month agokaranvp
1 year, 4 months agorichck102
1 year, 4 months agodedfef
1 year, 7 months agoaokisan
1 year, 10 months ago