exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 4 discussion

Actual exam question from Isaca's CISM
Question #: 4
Topic #: 1
[All CISM Questions]

When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?

  • A. Access control management
  • B. Change management
  • C. Configuration management
  • D. Risk management
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Viperhunter
Highly Voted 1 year ago
Selected Answer: D
Risk management is the process of identifying, assessing, and prioritizing risks to an organization, including the evaluation of existing controls and the selection of new controls based on changes in the business strategy. When the business strategy changes, it may introduce new risks or alter the significance of existing risks. Risk management allows organizations to adapt their information security controls to align with the evolving risk landscape. While access control management (option A), change management (option B), and configuration management (option C) are important processes within information security, risk management is the overarching process that guides the assessment of controls in the context of changing business strategies.
upvoted 10 times
...
ccsppractice
Most Recent 1 month, 3 weeks ago
Selected Answer: B
B. conduct a risk assessment. This step allows the information security manager to evaluate the potential risks introduced by the new regulatory requirement and understand its impact on the organization's existing controls. By identifying vulnerabilities and threats, the manager can prioritize actions and allocate resources effectively. Would you like to dive deeper into risk assessment methodologies or discuss other aspects of information security?
upvoted 1 times
...
CISSPST
12 months ago
Selected Answer: D
Viperhunter
upvoted 2 times
...
Soleandheel
1 year, 1 month ago
B. Change Management ..........Please don't trust all Chatgpt answers. Many of them are flawed. You have to explore deeper on some of these questions.
upvoted 1 times
AlexJacobson
10 months, 2 weeks ago
I agree that ChatGPT answers are wrong half the time, but how the hell change management evaluates current security controls and assist in selecting new ones? In this case, ChatGPT is correct and it's D - of all other answers, risk assessment is the closest we have for evaluating the controls and selecting new ones thriugh figuring out what are the current risks, what will new controls do to existing risk profile and what controls generally make sense for cost-effective risk management.
upvoted 1 times
...
...
pc2502
1 year, 4 months ago
Change management is the right answer as it asess information security control during changes. Risk management is only for assessing risk occurred due to changes
upvoted 4 times
...
pc2502
1 year, 4 months ago
Risk Management-> evaluation and Change Management->assessing as question is about evaluation so Risk Management is the rights answer
upvoted 1 times
...
pc2502
1 year, 4 months ago
1. Risk Mgmt- Risk management involves identifying, assessing, and mitigating risks that could impact an organization's objectives Gap analysis comes i picture:- when compare between current business' strategy to best in marked(regulatory)
upvoted 1 times
...
peelu
1 year, 6 months ago
Selected Answer: D
Risk management
upvoted 1 times
...
richck102
1 year, 7 months ago
D. Risk management
upvoted 1 times
...
Prasannacpw
2 years ago
Selected Answer: D
Risk Assessment is critical
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...