exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 689 discussion

Actual exam question from Isaca's CISM
Question #: 689
Topic #: 1
[All CISM Questions]

Which of the following sources is MOST useful when planning a business-aligned information security program?

  • A. Business impact analysis (BIA)
  • B. Information security policy
  • C. Security risk register
  • D. Enterprise architecture (EA)
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
03allen
11 months ago
Selected Answer: A
BIA here will define the criticality of the business and will guide the security program.
upvoted 3 times
...
REHAMAZZAM
1 year, 3 months ago
Selected Answer: A
A. Business impact analysis (BIA) The most useful source when planning a business-aligned information security program is a Business Impact Analysis (BIA). A BIA assesses the potential impacts of disruptions to business operations, identifying critical business processes, dependencies, and their associated risks. By understanding the business's priorities, objectives, and tolerance for disruption, organizations can tailor their information security program to align with business needs effectively. While options B, C, and D (Information security policy, Security risk register, and Enterprise architecture) are important components of an information security program, the BIA provides essential insights into business requirements and priorities, guiding the development of a program that is aligned with business objectives.
upvoted 4 times
...
AlexJacobson
1 year, 3 months ago
Selected Answer: D
CISM Exam Prep Guide (2nd edition): "Enterprise Architecture (EA) defines and documents the structure and process flow of the operations of an organization. It describes how different elements such as processes, systems, data, employees, and other infrastructure are integrated to achieve the organization's current and future objectives."
upvoted 3 times
...
CISSPST
1 year, 4 months ago
Selected Answer: D
Enterprise Architecture defines the relationship between and organizes the multiple moving parts in any organization, and thus aids in the alignment of its various components.
upvoted 1 times
...
Marcovic00
1 year, 6 months ago
Selected Answer: A
BIA is better, architecture doesnt always reveal security needs BIA does
upvoted 1 times
...
afc1019
1 year, 7 months ago
Selected Answer: A
A business impact analysis (BIA) is the MOST useful source when planning a business-aligned information security program. A BIA is a process of identifying and assessing the impact of a disruption to an organization's business operations. The results of a BIA can be used to prioritize information security resources and to develop a security program that is aligned with the organization's business goals. The other answer choices are also important for information security, but they are not as directly related to planning a business-aligned information security program as a BIA.
upvoted 1 times
...
Kunzle
1 year, 8 months ago
Selected Answer: D
Enterprise architecture provides a comprehensive view of the organization's strategy, business processes, information flows, technologies, and infrastructure. Aligning the information security program with the enterprise architecture ensures that security initiatives are in sync with the organization's overall objectives and infrastructure, thus ensuring both efficiency and effectiveness. While the other options are important components of a security program, the EA provides a broader view that encompasses all these elements and aligns them with business goals.
upvoted 2 times
...
oluchecpoint
1 year, 8 months ago
Selected Answer: A
The Business Impact Analysis (BIA) is a crucial step in information security program planning because it helps you understand the critical business processes, their dependencies, and the potential impact of security incidents or disruptions on these processes. This information is essential for aligning your security measures with the business's objectives and ensuring that your security program is focused on protecting what matters most to the organization.
upvoted 1 times
...
Goseu
1 year, 10 months ago
Selected Answer: D
D. EA for sure , that aligns business and IT .
upvoted 3 times
...
richck102
1 year, 10 months ago
Selected Answer: D
D. Enterprise architecture (EA)
upvoted 3 times
ddharia94
1 year, 10 months ago
How? Not even close. My vote for business impact analysis
upvoted 2 times
[Removed]
1 year, 9 months ago
From the CISM Review Manual, 27th Edition (Page 46): "The enterprise architecture (EA) provides a strategic context for the evolution of the IT system in response to the constantly changing needs of the business environment...It also provides a comprehensive view of the interdependencies among an enterprise's information system portfolios."
upvoted 3 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...