Certified Information Security Manager (CISM) — Question 344
Of the following, who is in the BEST position to evaluate business impacts?
Answer options
- A. Senior management
- B. Information security manager
- C. Process manager
- D. IT manager
Correct answer: C
Explanation
The Process manager is best suited to evaluate business impacts because they have a comprehensive understanding of the workflows and processes that drive the organization. Senior management may be focused on high-level strategy, while the Information security manager and IT manager are more concerned with their specific domains rather than overall business processes.