Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 2 Question 109 Discussion

Actual exam question for Isaca's CISM exam
Question #: 109
Topic #: 2
[All CISM Questions]

Which of the following sources is MOST useful when planning a business-aligned information security program?

Show Suggested Answer Hide Answer
Suggested Answer: C

A business-aligned information security program is one that supports the organization's business objectives and aligns the information security strategy with the business functions. A business impact analysis (BIA) is a process that identifies the critical business processes, assets, and functions of an organization, and assesses their potential impact in the event of a disruption or loss. A BIA helps to prioritize the information security requirements and controls that are needed to protect the organization's critical assets and functions from various threats and risks. Therefore, a BIA is one of the most useful sources when planning a business-aligned information security program.Reference= CISM Review Manual 15th Edition, page 254; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 229.

The most useful source when planning a business-aligned information security program is a Business Impact Analysis (BIA). A BIA is a process of identifying and evaluating the potential effects of disruptions to an organization's operations, and helps to identify the security controls and measures that should be implemented to reduce the impact of those disruptions. The BIA should include an assessment of the organization's information security posture, including its security policies, risk register, and enterprise architecture. With this information, organizations can develop an information security program that is aligned to the organization's business objectives.


Contribute your Thoughts:

0/2000 characters
Sherell
4 days ago
I lean towards the enterprise architecture (EA) since it provides a comprehensive view of the organization, but I could see how the BIA might be more directly aligned with security needs.
upvoted 0 times
...
Bulah
9 days ago
I remember a practice question where the security risk register was highlighted as essential for risk management, but I feel like the information security policy might also play a big role.
upvoted 0 times
...
Suzan
14 days ago
I think the Business Impact Analysis (BIA) is really important because it helps identify critical business functions, but I'm not entirely sure if it's the most useful source.
upvoted 0 times
...

Save Cancel