How can one think of cost benefit analysis if it is a regulatory requirement. There should be zero tolerance towards it. Otherwise the regulator will penalize the organization for non compliance. Regulators usually bring guidelines after analyzing risk.
It should be C - Legal and regulatory requirements applicable to IT can vary depending on the industry, region, and type of IT systems involved. Treating them as a risk to be assessed before developing a response is a best practice, as it helps the enterprise to identify potential impacts, assess the likelihood of occurrence, and develop a plan to mitigate the risks.
I havent done CISM but within GEIT, cost-benefit needs to be done always. Its part of the performance measurement approach, please refer figure 1.19 (in the 7th edition).
If cost is higher than benefits then why spending more to be complaint?
upvoted 1 times
...
...
This section is not available anymore. Please use the main Exam Page.CGEIT Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Manohar05
1 week agoChiraag
1 year agoFrank1480
1 year, 10 months agodtdtdt1977
3 years, 1 month agoJohn_Connor
3 years, 1 month agoGRamos
1 year, 11 months agoRamye
3 years ago