Which of the following should be considered FIRST when determining how to protect an organization's information assets?
When determining how to protect an organization's information assets, the first consideration should be the organization's business model because:
Contextual Risk Management: The business model dictates the types of data the organization processes, stores, and transmits.
Critical Asset Identification: Understanding how the business operates helps prioritize mission-critical systems and data.
Security Strategy Alignment: Ensures that security measures align with business objectives and requirements.
Regulatory Compliance: Different industries have unique compliance needs (e.g., healthcare vs. finance).
Other options analysis:
A . Prioritized inventory: Important but less foundational than understanding the business context.
C . Vulnerability assessments: Relevant later, after identifying critical business functions.
D . Risk reporting: Informs decisions but doesn't form the primary basis for protection strategies.
CCOA Official Review Manual, 1st Edition Reference:
Chapter 2: Risk Management and Business Impact: Emphasizes considering business objectives before implementing security controls.
Chapter 5: Strategic Security Planning: Discusses aligning security practices with business models.
Maira
1 month agoLorrine
2 months agoKathryn
2 months agoCarmen
2 months agoLong
2 months agoDyan
2 months agoCarman
2 months agoAlyssa
3 months agoKeena
3 months agoLeontine
3 months agoLevi
4 months agoSharen
4 months agoVirgie
4 months agoNickie
4 months agoAlex
4 months agoLottie
4 months agoTish
5 months agoArlette
5 months agoJani
5 months agoAnnabelle
5 months agoCherry
5 months agoFanny
6 months agoCharlesetta
6 months agoDesirae
6 months agoRashida
6 months agoNorah
20 days agoHyman
26 days agoDante
1 month agoAracelis
1 month agoJospeh
5 months ago