A business case best demonstrates return on investment in risk management when requesting investment in new tools. In CISM, a business case connects the proposed investment to business objectives, risk reduction, cost, benefits, alternatives, and expected value. For a BYOD policy expanded to include wearable technologies, management needs to understand why new tools are required, what risks they reduce, what costs are involved, and how the investment supports acceptable risk levels. A risk assessment is an important input because it identifies and analyzes risks associated with wearable technologies, but it does not itself demonstrate ROI. A risk audit report provides assurance or findings, not the investment justification. A BIA supports continuity planning and impact prioritization, but it is not the best document for presenting investment value. The strategy committee needs a decision-oriented justification. Therefore, the business case is the best answer because it translates security needs and risk reduction into management-level investment rationale.
[References:, ISACA CISM Review Manual, Information Security Program Development and Management — business cases and security investment justification, ISACA CISM Exam Content Outline, Domain 3: Information Security Program Development and Management, , ]
Submit