Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 667 discussion

Actual exam question from Isaca's CISM
Question #: 667
Topic #: 1
[All CISM Questions]

Of the following, who is in the BEST position to evaluate business impacts?

  • A. Senior management
  • B. Information security manager
  • C. Process manager
  • D. IT manager
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Dravidian
Highly Voted 1 year, 6 months ago
Selected Answer: C
Just because senior management is ultimately responsible and accountable does not mean they are the best to evaluate the impact since it's impossible to be aware of every detail of every process in an organization. A process owner would be the best resource to know everything about their process and hence the best to evaluate the impact to their process.
upvoted 14 times
...
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: A
A. Senior management is in the BEST position to evaluate business impacts, as they are responsible for the overall strategy and direction of the organization, and have the authority and access to resources to make decisions that affect the entire organization.
upvoted 11 times
AlexJacobson
9 months, 3 weeks ago
Then again, senior management is too high to be able to EVALUATE business impact of some low-level process.
upvoted 2 times
...
giovi
1 year, 8 months ago
Agree with you
upvoted 3 times
...
...
Raj91188
Most Recent 2 months ago
Selected Answer: C
Agree with Dravidian - senior management is ultimately responsible and accountable does not mean they are the best to evaluate the impact since it's impossible to be aware of every detail of every process in an organization.
upvoted 1 times
...
03allen
4 months, 3 weeks ago
Selected Answer: C
I reckon the best answer would be a product/ process owner, who understands the business progress the most.
upvoted 1 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: A
I'm actually gonna go ahead an point out that it is said "business impactS" (plural). So senior management is more relevant than a process manager. Yeah, I know it's a bit of a stretch, but it seems to me that's a mini-hint.
upvoted 1 times
...
Marcovic00
12 months ago
Selected Answer: C
process manager will have a better visibility but the senior manager will have overall visibility to take a decision at the end
upvoted 1 times
...
secdoc
1 year, 1 month ago
Senior Management is at the 50k ft view level. Definitely C.
upvoted 2 times
...
koala_lay
1 year, 1 month ago
Selected Answer: A
A. Senior management
upvoted 1 times
...
koala_lay
1 year, 1 month ago
Senior management is in the best position to evaluate business impacts. Senior management typically has a broader perspective on the overall business operations and goals. They are responsible for making strategic decisions and have a better understanding of the potential risks and impacts on the organization as a whole. Additionally, senior management has the authority to allocate resources and make changes to mitigate any identified risks. While other roles such as the information security manager, process manager, and IT manager may have specialized knowledge and expertise in their respective areas, senior management has the overall authority and responsibility to evaluate the business impacts.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: A
Senior management has a strategic perspective, information security managers focus on security-related impacts, process managers specialize in process-related impacts, and IT managers assess IT-related impacts. The choice of who should evaluate business impacts should be based on the specific circumstances and the expertise required to make informed assessments. Often, a collaborative approach involving multiple stakeholders may be necessary to comprehensively evaluate business impacts.
upvoted 1 times
...
justx
1 year, 3 months ago
Selected Answer: A
I choose A, Everybody reports to Senior Management ..including process manager. Senior management is aware or should be aware of everything going on, or affecting the org. So they can evaluate the business impacts. They have the overall picture to do that, process manager only have a partial view of his/ her process.
upvoted 2 times
...
Nillanash
1 year, 3 months ago
I agree with Dravidian that the answer is C-Process Manager. Senior management are ultimately responsible for an organization's risk, but don't evaluate business impacts . The process manger does this .
upvoted 2 times
...
wickhaarry
1 year, 3 months ago
C. Process manager
upvoted 2 times
...
richck102
1 year, 4 months ago
A. Senior management
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: A
Evaluating business impacts involves understanding how potential incidents, disruptions, or changes can affect the organization's operations, financials, reputation, and overall business continuity. Senior management has the authority and perspective to assess these impacts holistically and make informed decisions about risk management, resource allocation, and prioritization.
upvoted 2 times
...
Pabl0T0rrez
1 year, 6 months ago
A. Senior management is in the best position to evaluate business impacts because they have a holistic view of the organization and its operations. The information security manager is responsible for protecting the organization's information assets.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...