Certified Information Security Manager CISM · Free Practice Question Easy

Question 41

In the context of information risk management, what is the FIRST step an organization should take?
  • A A) Identifying assets and their value to the organization
  • B B) Implementing controls to mitigate identified risks.
  • C C) Assessing the potential impact of threats.
  • D D) Developing a risk management policy.
Reveal correct answer

Correct answer: A

Explanation

Correct Answer: A) Identifying assets and their value to the organization. Explanation: Correct (A): The first step in risk management is to identify the assets and understand their value to the organization, which sets the foundation for subsequent risk assessment and mitigation strategies. Incorrect (B): Implementing controls comes after identifying and assessing risks. Incorrect (C): Assessing the impact of threats is part of risk assessment, which occurs after identifying assets. Incorrect (D): Developing a policy is important but should be based on an understanding of the organization's assets and their importance.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need