Which of the following should be considered FIRST when determining how to protect an organization's information assets?
When determining how to protect an organization's information assets, the first consideration should be the organization's business model because:
Contextual Risk Management: The business model dictates the types of data the organization processes, stores, and transmits.
Critical Asset Identification: Understanding how the business operates helps prioritize mission-critical systems and data.
Security Strategy Alignment: Ensures that security measures align with business objectives and requirements.
Regulatory Compliance: Different industries have unique compliance needs (e.g., healthcare vs. finance).
Other options analysis:
A . Prioritized inventory: Important but less foundational than understanding the business context.
C . Vulnerability assessments: Relevant later, after identifying critical business functions.
D . Risk reporting: Informs decisions but doesn't form the primary basis for protection strategies.
CCOA Official Review Manual, 1st Edition Reference:
Chapter 2: Risk Management and Business Impact: Emphasizes considering business objectives before implementing security controls.
Chapter 5: Strategic Security Planning: Discusses aligning security practices with business models.
Alyssa
9 hours agoKeena
6 days agoLeontine
11 days agoLevi
16 days agoSharen
21 days agoVirgie
26 days agoNickie
1 month agoAlex
1 month agoLottie
1 month agoTish
2 months agoArlette
2 months agoJani
2 months agoAnnabelle
2 months agoCherry
2 months agoFanny
3 months agoCharlesetta
3 months agoDesirae
3 months agoRashida
3 months agoJospeh
2 months ago