Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 344 discussion

Actual exam question from Isaca's CISM
Question #: 344
Topic #: 1
[All CISM Questions]

During the due diligence phase of an acquisition, the MOST important course of action for an information security manager is to:

  • A. review the state of security awareness
  • B. review information security policies
  • C. perform a risk assessment
  • D. perform a gap analysis
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Funshykay
Highly Voted 1 year, 10 months ago
Selected Answer: C
Agreed> For Third-party risk mgt programs, it is important for Information security to conduct risk assessment and document all findings for all short-listed vendors which in turns help procuremnent/businness to make an informed decision for proper selcetion.
upvoted 8 times
...
AlexJacobson
Most Recent 10 months ago
Selected Answer: C
This is actually a tough one. B, C and D are all correct in a way. One of the definitions of due diligence in M&A is the following: "Due diligence allows the buyer in the M&A process to confirm hitherto undisclosed details about the selling company's financials, contracts, personnel and customers. In other words, it allows the buyer to obtain a complete picture of the business being acquired." So infosec manager should look into their security policies and processes (B), see how much they differ (D) and assess the risks based on that (C). So if I'd have to pick the most comprehensive answer, I'd say C. But I'm not 100% on this.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
C. Perform a risk assessment Performing a risk assessment is crucial because it helps identify potential vulnerabilities and threats associated with the acquisition target. This assessment allows the acquiring organization to understand the security risks and make informed decisions about the acquisition. While reviewing security awareness, information security policies, and performing gap analysis are all important aspects of the due diligence process, assessing the specific risks associated with the acquisition target takes precedence because it forms the foundation for addressing security concerns and making risk-based decisions.
upvoted 2 times
...
Agamennore
1 year, 2 months ago
Selected Answer: C
Risk Assessment is more appropriate
upvoted 1 times
...
karanvp
1 year, 5 months ago
Due diligence phase is a comprehensive assessment of records of the target company prior to closing a merger or acquisition (M&A) deal
upvoted 1 times
...
richck102
1 year, 5 months ago
C. perform a risk assessment
upvoted 1 times
...
aokisan
1 year, 11 months ago
Selected Answer: D
in phase of acquisition, gap between A and B is needed.
upvoted 2 times
justx
3 months ago
But you need to know the state of A and B first to be able to compare them. New acquisition is new and there is no way to know the current state without a risk assessment first.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...