Certified Information Security Manager CISM · Free Practice Question Easy
Question 41
In the context of information risk management, what is the FIRST step an organization should take?
- A A) Identifying assets and their value to the organization
- B B) Implementing controls to mitigate identified risks.
- C C) Assessing the potential impact of threats.
- D D) Developing a risk management policy.
Reveal correct answer
Correct answer: A
Explanation
Correct Answer: A) Identifying assets and their value to the organization. Explanation: Correct (A): The first step in risk management is to identify the assets and understand their value to the organization, which sets the foundation for subsequent risk assessment and mitigation strategies. Incorrect (B): Implementing controls comes after identifying and assessing risks. Incorrect (C): Assessing the impact of threats is part of risk assessment, which occurs after identifying assets. Incorrect (D): Developing a policy is important but should be based on an understanding of the organization's assets and their importance.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
