Certified Information Security Manager (CISM) — Question 349
Which of the following will provide the MOST guidance when deciding the level of protection for an information asset?
Answer options
- A. Impact on information security program
- B. Cost of controls
- C. Impact to business function
- D. Cost to replace
Correct answer: C
Explanation
The correct answer, C, highlights the importance of assessing how the protection of an information asset affects business operations, as this directly impacts the organization's effectiveness and continuity. The other options, while relevant, do not provide as comprehensive a view of the needs for protection as the impact on business function does.