Certified Information Security Manager CISM · Free Practice Question Medium
Question 19
What is the primary factor an information security manager should assess when selecting controls to counteract emerging threat vectors?
- A The potential financial impact of a threat
- B The adaptability of controls to evolving threats
- C The likelihood of threat occurrence
- D The alignment with existing security policies
Reveal correct answer
Correct answer: A
Explanation
The Correct Answer: The potential financial impact of a threat: This option is the best answer as it emphasizes assessing the financial consequences associated with a threat, which aligns security controls with business objectives. Understanding the financial impact is crucial because it helps prioritize threats based on potential damage to the organization, ensuring strategic allocation of resources where they are needed most to protect the organization's financial interests and stability. The Incorrect Answers: The likelihood of threat occurrence: While understanding the likelihood of a threat is important, it doesn't directly address the business impact. Focusing solely on likelihood might lead to overemphasizing frequent but low-impact threats, potentially diverting resources from more damaging but less probable threats. The alignment with existing security policies: Although alignment with existing policies is necessary, it does not account for the dynamic nature of emerging threats. Policies may need to be updated or adapted to remain effective against new threats, hence this option lacks consideration of an evolving threat landscape. The adaptability of controls to evolving threats: While adaptability is a valuable trait for security controls, it should not be the primary assessment factor. It focuses more on the characteristics of controls themselves rather than the broader implications of threats, such as their potential impact on the organization.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
