CISM Certified Information Security Manager – Question0406

The decision on whether new risks should fall under periodic or event-driven reporting should be based on which of the following?

A.
Mitigating controls
B. Visibility of impact
C. Likelihood of occurrence
D. Incident frequency

Correct Answer: B

Explanation:

Explanation: Visibility of impact is the best measure since it manages risks to an organization in the timeliest manner. Likelihood of occurrence and incident frequency are not as relevant. Mitigating controls is not a determining factor on incident reporting.