Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 4 Question 108 Discussion

Which of the following BEST facilitates an information security manager's efforts to obtain senior management commitment for an information security program?
D) Communicating the residual risk
A) Presenting evidence of inherent risk
B) Reporting the security maturity level
C) Presenting compliance requirements

Isaca CISM Exam - Topic 4 Question 108 Discussion

Actual exam question for Isaca's CISM exam
Question #: 108
Topic #: 4
[All CISM Questions]

Which of the following BEST facilitates an information security manager's efforts to obtain senior management commitment for an information security program?

Show Suggested Answer Hide Answer
Suggested Answer: D

Communicating the residual risk is the best way to facilitate an information security manager's efforts to obtain senior management commitment for an information security program. The residual risk is the level of risk that remains after applying the security controls and mitigation measures. The residual risk reflects the effectiveness and efficiency of the information security program, as well as the potential impact and exposure of the organization. The information security manager should communicate the residual risk to the senior management in a clear, concise, and relevant manner, using quantitative or qualitative methods, such as risk matrices, heat maps, dashboards, or reports. The communication of the residual risk should also include the comparison with the inherent risk, which is the level of risk before applying any security controls, and the risk appetite, which is the level of risk that the organization is willing to accept. The communication of the residual risk should help the senior management to understand the value and performance of the information security program, as well as the need and justification for further investment or improvement. Presenting evidence of inherent risk, reporting the security maturity level, and presenting compliance requirements are all important aspects of the information security program, but they are not the best ways to obtain senior management commitment. These aspects may not directly demonstrate the benefits or outcomes of the information security program, or they may not align with the business objectives or priorities of the organization. For example, presenting evidence of inherent risk may show the potential threats and vulnerabilities that the organization faces, but it may not indicate how the information security program addresses or reduces them. Reporting the security maturity level may show the progress and status of the information security program, but it may not relate to the risk level or the business impact. Presenting compliance requirements may show the legal or regulatory obligations that the organization must fulfill, but it may not reflect the actual security needs or goals of the organization.Therefore, communicating the residual risk is the best way to obtain senior management commitment for an information security program, as it shows the results and value of the information security program for the organization.Reference= CISM Review Manual 2023, page 411; CISM Practice Quiz2


Contribute your Thoughts:

0/2000 characters
Louvenia
11 hours ago
I prefer C. Compliance requirements are crucial for management.
upvoted 0 times
...
Beatriz
6 days ago
I think A is the best choice. Inherent risk really grabs attention.
upvoted 0 times
...
Clarence
11 days ago
Reporting maturity level (B) is just fluff. Focus on the risks!
upvoted 0 times
...
Justa
16 days ago
Wait, are we really saying compliance isn’t the top priority?
upvoted 0 times
...
Lettie
2 months ago
D makes sense too, but it’s all about how you present it.
upvoted 0 times
...
Larae
2 months ago
I think C is more important. Compliance is key for management.
upvoted 0 times
...
Tamra
2 months ago
A is definitely the way to go. Inherent risk speaks volumes!
upvoted 0 times
...
Pansy
3 months ago
Wait, are we really prioritizing inherent risk over compliance?
upvoted 0 times
...
Felicitas
3 months ago
Communicating residual risk? Sounds a bit vague to me.
upvoted 0 times
...
Aleisha
3 months ago
Reporting the security maturity level shows progress.
upvoted 0 times
...
Lizbeth
3 months ago
I think compliance requirements are more convincing.
upvoted 0 times
...
Cletus
3 months ago
Presenting evidence of inherent risk is key!
upvoted 0 times
...
Thora
3 months ago
Communicating residual risk sounds familiar, but I’m not confident it would really convince senior management compared to the other options.
upvoted 0 times
...
Avery
4 months ago
I feel like compliance requirements are important, but they might not be the strongest motivator for senior management commitment.
upvoted 0 times
...
Rashad
4 months ago
I remember a practice question where reporting the security maturity level seemed to help in gaining support, but I wonder if it’s the most effective here.
upvoted 0 times
...
Lelia
4 months ago
I think presenting evidence of inherent risk might be the best option, but I'm not entirely sure if that resonates enough with senior management.
upvoted 0 times
...

Save Cancel