Certified Information Security Manager (CISM) — Question 608
Which of the following analyses will BEST identify the external influences to an organization's information security?
Answer options
- A. Threat analysis
- B. Business impact analysis (BIA)
- C. Gap analysis
- D. Vulnerability analysis
Correct answer: A
Explanation
The correct answer is A, as threat analysis focuses specifically on identifying potential external threats to information security. The other analyses, while important, do not primarily focus on external influences; for instance, BIA assesses the impact of disruptions, gap analysis evaluates discrepancies between current and desired states, and vulnerability analysis looks for weaknesses within the system.