According to the Certified Information Security Manager (CISM) Review Manual: "Decisions to accept residual risk should be based on considerations such as the cost-effectiveness of additional mitigation, the criticality of the asset to the enterprise’s mission, the asset’s value and the impact of the asset’s loss." (CISM Review Manual 15th Edition, p. 124)
The MOST important criterion when deciding whether to accept residual risk is the cost of additional mitigation. Therefore, the correct answer is option C.
I'm torn between B and, but leaning more towards C.
If additional mitigation is not cost effective and the risk is still deemed too high, then the only other choice would be risk avoidance. But if that isn't possible, the only thing a business can do is accept the residual risk.
ALE is important for determining a a potential loss an asset would suffer due to a threat realization over a year. But you can reduce ALE up to a point after which it stops being cost effective.
ANSWER C :
The security manager would be most concerned with whether residual risk would be reduced by a greater amount than the cost of adding additional controls. The other choices, although relevant, would not be as important.
even if the risk is equal or greater than the asset value, the annual rate of occurrence matters.
so I think B
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
[Removed]
Highly Voted 11 months, 2 weeks agoSouvik124
Highly Voted 1 year, 4 months agocangurer
1 year, 3 months ago1899f17
Most Recent 1 month, 2 weeks agoMarcelus1714
5 months agoAlexJacobson
5 months, 2 weeks agoPOWNED
5 months, 2 weeks agoEvedzy
6 months, 1 week agoSaisharan
9 months agoBl1024
9 months, 2 weeks agorichck102
1 year agowello
1 year ago