Q: 14
Which of the following MUST be defined in order for an information security manager to evaluate
the appropriateness of controls currently in place?
Options
Discussion
Totally C. Risk appetite has to come first if you want to judge control effectiveness.
C tbh, that's what pops up in all the official guides and exam reports. I’d review the risk management domain more.
Probably C, not B. The risk appetite is needed up front or you can fall for the framework trap.
Seriously, ISACA loves this risk appetite stuff every exam. Why not B?
Yeah I agree, C is the key here. You can't really say if your controls are too weak or too strong unless you've got the risk appetite defined first. Policies and frameworks help, but the appetite sets that bar. Pretty confident but let me know if you see it differently.
Its C. You need to know the organization's risk appetite to judge if existing controls are enough or overkill. Without that baseline, there's no way to say what level of risk is acceptable. Pretty sure about this, but open to other takes.
Be respectful. No spam.
Question 14 of 35