Isaca Certified Information Security Manager CISM Question # 251 Topic 26 Discussion

Isaca Certified Information Security Manager CISM Question # 251 Topic 26 Discussion

CISM Exam Topic 26 Question 251 Discussion:
Question #: 251
Topic #: 26

Which of the following is the BEST strategy when determining an organization’s approach to risk treatment?


A.

Advancing the maturity of existing controls based on risk tolerance


B.

Prioritizing controls that directly mitigate the organization's most critical risks


C.

Implementing risk mitigation controls that are considered quick wins


D.

Implementing a one-size-fits-all set of controls across all organizational units


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.