Which of the following should be done FIRST when selecting performance metrics to report on the vendor risk management process?
Correct Answer: D
"A better approach is the development of operational metrics, which are usually easily discovered and measured. The next step is to transform those operational metrics into different metrics, stated in business terms, FOR BUSINESS AUDIENCES. In a given organization, a security program might employ two, three, or more layers of metrics, usually related to each other, and stated in relevant technical or business terms for each RESPECTIVE AUDIENCE." - CISM All-In-One Study Guide, P.H. Gregory, 1st Edition
CISM Exam Question 117
An information security manager learns that a departmental system is out of compliance with the information security policy's password strength requirements. Which of the following should be the information security manager's FIRST course of action?
Correct Answer: C
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
CISM Exam Question 118
Which of the following is the MOST important reason for an organization to develop an information security governance program?
Correct Answer: B
Section: INFORMATION SECURITY GOVERNANCE
CISM Exam Question 119
When personal information is transmitted across networks, there MUST be adequate controls over:
Correct Answer: B
Section: INFORMATION SECURITY GOVERNANCE Explanation: Privacy protection is necessary to ensure that the receiving party has the appropriate level of protection of personal data. Change management primarily protects only the information, not the privacy of the individuals. Consent is one of the protections that is frequently, but not always, required. Encryption is a method of achieving the actual control, but controls over the devices may not ensure adequate privacy protection and, therefore, is a partial answer.
CISM Exam Question 120
When choosing the best controls to mitigate risk to acceptable levels, the information security manager's decision should be MAINLY driven by:
Correct Answer: D
Explanation Cost-benefit analysis (CBA) is a method of comparing the costs and benefits of different alternatives for achieving a desired outcome. CBA can help information security managers to choose the best controls to mitigate risk to acceptable levels by providing a rational and objective basis for decision making. CBA can also help information security managers to justify their choices to senior management, stakeholders, and auditors by demonstrating the value and return on investment of the selected controls. CBA can also help information security managers to prioritize and allocate resources for implementing and maintaining the controls12. CBA involves the following steps12: Identify the objectives and scope of the analysis Identify the alternatives and options for achieving the objectives Identify and quantify the costs and benefits of each alternative Compare the costs and benefits of each alternative using a common metric or criteria Select the alternative that maximizes the net benefit or minimizes the net cost Perform a sensitivity analysis to test the robustness and validity of the results Document and communicate the results and recommendations CBA is mainly driven by the information security manager's decision, but it can also take into account other factors such as best practices, control frameworks, and regulatory requirements. However, these factors are not the primary drivers of CBA, as they may not always reflect the specific needs and context of the organization. Best practices are general guidelines or recommendations that may not suit every situation or environment. Control frameworks are standardized models or methodologies that may not cover all aspects or dimensions of information security. Regulatory requirements are mandatory rules or obligations that may not address all risks or threats faced by the organization. Therefore, CBA is the best method to choose the most appropriate and effective controls to mitigate risk to acceptable levels, as it considers the costs and benefits of each control in relation to the organization's objectives, resources, and environment12. References = CISM Domain 2: Information Risk Management (IRM) [2022 update], Five Key Considerations When Developing Information Security Risk Treatment Plans