Which of the following should be considered FIRST when determining how to protect an organization's information assets?
When determining how to protect an organization's information assets, the first consideration should be the organization's business model because:
Contextual Risk Management: The business model dictates the types of data the organization processes, stores, and transmits.
Critical Asset Identification: Understanding how the business operates helps prioritize mission-critical systems and data.
Security Strategy Alignment: Ensures that security measures align with business objectives and requirements.
Regulatory Compliance: Different industries have unique compliance needs (e.g., healthcare vs. finance).
Other options analysis:
A . Prioritized inventory: Important but less foundational than understanding the business context.
C . Vulnerability assessments: Relevant later, after identifying critical business functions.
D . Risk reporting: Informs decisions but doesn't form the primary basis for protection strategies.
CCOA Official Review Manual, 1st Edition Reference:
Chapter 2: Risk Management and Business Impact: Emphasizes considering business objectives before implementing security controls.
Chapter 5: Strategic Security Planning: Discusses aligning security practices with business models.
Lorrine
1 day agoKathryn
6 days agoCarmen
11 days agoLong
17 days agoDyan
22 days agoCarman
27 days agoAlyssa
2 months agoKeena
2 months agoLeontine
2 months agoLevi
2 months agoSharen
2 months agoVirgie
2 months agoNickie
3 months agoAlex
3 months agoLottie
3 months agoTish
3 months agoArlette
3 months agoJani
3 months agoAnnabelle
4 months agoCherry
4 months agoFanny
4 months agoCharlesetta
4 months agoDesirae
5 months agoRashida
5 months agoJospeh
4 months ago