Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 4 Question 108 Discussion

Actual exam question for Isaca's CISM exam
Question #: 108
Topic #: 4
[All CISM Questions]

Which of the following BEST facilitates an information security manager's efforts to obtain senior management commitment for an information security program?

Show Suggested Answer Hide Answer
Suggested Answer: D

Communicating the residual risk is the best way to facilitate an information security manager's efforts to obtain senior management commitment for an information security program. The residual risk is the level of risk that remains after applying the security controls and mitigation measures. The residual risk reflects the effectiveness and efficiency of the information security program, as well as the potential impact and exposure of the organization. The information security manager should communicate the residual risk to the senior management in a clear, concise, and relevant manner, using quantitative or qualitative methods, such as risk matrices, heat maps, dashboards, or reports. The communication of the residual risk should also include the comparison with the inherent risk, which is the level of risk before applying any security controls, and the risk appetite, which is the level of risk that the organization is willing to accept. The communication of the residual risk should help the senior management to understand the value and performance of the information security program, as well as the need and justification for further investment or improvement. Presenting evidence of inherent risk, reporting the security maturity level, and presenting compliance requirements are all important aspects of the information security program, but they are not the best ways to obtain senior management commitment. These aspects may not directly demonstrate the benefits or outcomes of the information security program, or they may not align with the business objectives or priorities of the organization. For example, presenting evidence of inherent risk may show the potential threats and vulnerabilities that the organization faces, but it may not indicate how the information security program addresses or reduces them. Reporting the security maturity level may show the progress and status of the information security program, but it may not relate to the risk level or the business impact. Presenting compliance requirements may show the legal or regulatory obligations that the organization must fulfill, but it may not reflect the actual security needs or goals of the organization.Therefore, communicating the residual risk is the best way to obtain senior management commitment for an information security program, as it shows the results and value of the information security program for the organization.Reference= CISM Review Manual 2023, page 411; CISM Practice Quiz2


Contribute your Thoughts:

0/2000 characters
Lizbeth
24 hours ago
I think compliance requirements are more convincing.
upvoted 0 times
...
Cletus
6 days ago
Presenting evidence of inherent risk is key!
upvoted 0 times
...
Thora
11 days ago
Communicating residual risk sounds familiar, but I’m not confident it would really convince senior management compared to the other options.
upvoted 0 times
...
Avery
16 days ago
I feel like compliance requirements are important, but they might not be the strongest motivator for senior management commitment.
upvoted 0 times
...
Rashad
22 days ago
I remember a practice question where reporting the security maturity level seemed to help in gaining support, but I wonder if it’s the most effective here.
upvoted 0 times
...
Lelia
27 days ago
I think presenting evidence of inherent risk might be the best option, but I'm not entirely sure if that resonates enough with senior management.
upvoted 0 times
...

Save Cancel