A. Business impact analysis (BIA)
The most useful source when planning a business-aligned information security program is a Business Impact Analysis (BIA). A BIA assesses the potential impacts of disruptions to business operations, identifying critical business processes, dependencies, and their associated risks. By understanding the business's priorities, objectives, and tolerance for disruption, organizations can tailor their information security program to align with business needs effectively. While options B, C, and D (Information security policy, Security risk register, and Enterprise architecture) are important components of an information security program, the BIA provides essential insights into business requirements and priorities, guiding the development of a program that is aligned with business objectives.
CISM Exam Prep Guide (2nd edition):
"Enterprise Architecture (EA) defines and documents the structure and process flow of the operations of an organization. It describes how different elements such as processes, systems, data, employees, and other infrastructure are integrated to achieve the organization's current and future objectives."
Enterprise Architecture defines the relationship between and organizes the multiple moving parts in any organization, and thus aids in the alignment of its various components.
A business impact analysis (BIA) is the MOST useful source when planning a business-aligned information security program. A BIA is a process of identifying and assessing the impact of a disruption to an organization's business operations. The results of a BIA can be used to prioritize information security resources and to develop a security program that is aligned with the organization's business goals. The other answer choices are also important for information security, but they are not as directly related to planning a business-aligned information security program as a BIA.
Enterprise architecture provides a comprehensive view of the organization's strategy, business processes, information flows, technologies, and infrastructure. Aligning the information security program with the enterprise architecture ensures that security initiatives are in sync with the organization's overall objectives and infrastructure, thus ensuring both efficiency and effectiveness. While the other options are important components of a security program, the EA provides a broader view that encompasses all these elements and aligns them with business goals.
The Business Impact Analysis (BIA) is a crucial step in information security program planning because it helps you understand the critical business processes, their dependencies, and the potential impact of security incidents or disruptions on these processes. This information is essential for aligning your security measures with the business's objectives and ensuring that your security program is focused on protecting what matters most to the organization.
From the CISM Review Manual, 27th Edition (Page 46):
"The enterprise architecture (EA) provides a strategic context for the evolution of the IT system in response to the constantly changing needs of the business environment...It also provides a comprehensive view of the interdependencies among an enterprise's information system portfolios."
upvoted 3 times
...
...
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
03allen
11 months agoREHAMAZZAM
1 year, 3 months agoAlexJacobson
1 year, 3 months agoCISSPST
1 year, 4 months agoMarcovic00
1 year, 6 months agoafc1019
1 year, 7 months agoKunzle
1 year, 8 months agooluchecpoint
1 year, 8 months agoGoseu
1 year, 10 months agorichck102
1 year, 10 months agoddharia94
1 year, 10 months ago[Removed]
1 year, 9 months ago