Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Exam CISM Topic 3 Question 62 Discussion

Actual exam question for Isaca's CISM exam
Question #: 62
Topic #: 3
[All CISM Questions]

Which of the following is the MOST important factor in an organization's selection of a key risk indicator (KRI)?

Show Suggested Answer Hide Answer
Suggested Answer: A

When preventive controls to appropriately mitigate risk are not feasible, the most important action for the information security manager is to manage the impact, which means taking measures to reduce the likelihood or severity of the consequences of the risk. Managing the impact can involve using alternative controls, such as engineering, administrative, or personal protective controls, that can lower the exposure or harm to the organization. The other options, such as identifying unacceptable risk levels, assessing vulnerabilities, or evaluating potential threats, are part of the risk assessment process, but they are not actions to mitigate risk when preventive controls are not feasible. Reference:

https://bcmmetrics.com/risk-mitigation-evaluating-your-controls/

https://www.osha.gov/safety-management/hazard-prevention

https://www.cdc.gov/niosh/topics/hierarchy/default.html


Contribute your Thoughts:

Ardella
1 months ago
Can we get a 'None of the Above' option? I'm feeling more confused than a cat on a hot tin roof here.
upvoted 0 times
...
Leonie
1 months ago
ROI? Really? This isn't a get-rich-quick scheme, it's risk management. I say go with D - criticality of information all the way!
upvoted 0 times
Ruth
1 days ago
Compliance requirements should also be considered to avoid legal issues.
upvoted 0 times
...
Julio
6 days ago
I agree, criticality of information is key for risk management.
upvoted 0 times
...
Jeniffer
10 days ago
I agree, criticality of information is crucial for selecting key risk indicators.
upvoted 0 times
...
...
Lynelle
1 months ago
Hmm, I'm gonna go with target audience. I mean, what's the point of a KRI if it doesn't resonate with the people who need to use it?
upvoted 0 times
...
Jody
2 months ago
Compliance requirements are a no-brainer. If the KRI doesn't meet regulatory standards, it's pretty much useless, right?
upvoted 0 times
Gracie
13 days ago
Compliance requirements should always be the main focus when choosing a key risk indicator.
upvoted 0 times
...
Shawnta
25 days ago
I agree, compliance is a top priority when selecting a KRI.
upvoted 0 times
...
Elke
1 months ago
Compliance requirements are definitely crucial. Without meeting regulations, the KRI is ineffective.
upvoted 0 times
...
...
Hubert
2 months ago
I think the criticality of information is the most important factor in selecting a KRI. After all, if the information isn't critical, why bother tracking it?
upvoted 0 times
Ciara
1 days ago
Return on investment is always a factor, we need to make sure we are getting value from tracking these KRIs.
upvoted 0 times
...
Kristeen
6 days ago
Target audience is important too, we need to focus on what matters most to them.
upvoted 0 times
...
Coletta
15 days ago
Compliance requirements should also be considered, we need to ensure we are meeting all regulations.
upvoted 0 times
...
Gladys
1 months ago
I agree, the criticality of information is crucial for selecting a KRI.
upvoted 0 times
...
...
Brande
2 months ago
But don't you think the target audience should also be considered?
upvoted 0 times
...
Della
3 months ago
I disagree, I believe the criticality of information is the key factor.
upvoted 0 times
...
Brande
3 months ago
I think compliance requirements are the most important factor.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77