exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 622 discussion

Actual exam question from Isaca's CISM
Question #: 622
Topic #: 1
[All CISM Questions]

Which of the following BEST enables an organization to appropriately prioritize information security-focused projects?

  • A. Return on investment (ROI)
  • B. Privacy compliance requirements
  • C. Organizational risk appetite
  • D. Historical security incidents
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 2 months ago
Selected Answer: C
The Correct Answer is (C) Organizational Risk Appetite as the focus is on an information security-focused project, while the others are not. (i.e. need to know what level of risk is important to know how to prioritize) Rationale: A. Return on investment (ROI) is a financial instrument that looks for the best possible return. While this is ideal for projects that make money, this isn't ideal for security cause security projects cost money. Using an ROI model will make everything just a race to the bottom. Instead, it should be focused on risk. B. Privacy compliance requirements: Compliance does not mean secure. D. Historical security incidents: Past performance does not mean that it is reflective of future occurrences. It is only a context of what has occurred in the past.
upvoted 8 times
...
Souvik124
Highly Voted 1 year, 4 months ago
The best option that enables an organization to appropriately prioritize information security-focused projects is organizational risk appetite.
upvoted 5 times
...
d7a2ba6
Most Recent 3 weeks, 3 days ago
Selected Answer: A
prioritize: determine the order for dealing with (a series of items or tasks) according to their relative importance. Risk apetite is not good for prioritizing as you will have only two buckets. Over and under the risk apetite. As information security-focused projects support the business goals, have positive impact on the bsuness, you can calculate the ROI, so you will impement those that have the biggest gains.
upvoted 1 times
...
AlexJacobson
5 months, 2 weeks ago
Selected Answer: C
This question is just intentionally made complicated, but is essentially asking "what type stuff do you prioritize"? The logical answer is "the ones that carry the most risk" (i.e. are most impactful), therefore you look at business' risk appetite and determine what's outside of that and work on that first.
upvoted 2 times
...
Kunzle
10 months ago
Selected Answer: C
This reflects the amount and type of risk an organization is willing to pursue or retain. Understanding the organization's risk appetite can help in prioritizing security projects that address the most significant and unacceptable risks first.
upvoted 1 times
...
richck102
1 year ago
A. Return on investment (ROI)
upvoted 1 times
...
aokisan
1 year, 6 months ago
Selected Answer: A
priority is decided on ROI.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago