CISM Certified Information Security Manager – Question0402

The MOST effective way to incorporate risk management practices into existing production systems is through:

A.
policy development.
B. change management.
C. awareness training.
D. regular monitoring.

Correct Answer: B

Explanation:

Explanation:
Change is a process in which new risks can be introduced into business processes and systems. For this reason, risk management should be an integral component of the change management process. Policy development, awareness training and regular monitoring, although all worthwhile activities, are not as effective as change management.