PrepAway - Latest Free Exam Questions & Answers

which of the following?

Computer security should be first and foremost which of the following?

PrepAway - Latest Free Exam Questions & Answers

A.
Cover all identified risks

B.
Be cost-effective.

C.
Be examined in both monetary and non-monetary terms.

D.
Be proportionate to the value of IT systems.

Explanation:
Each organization is different in its size, security posture, threat profile, and security budget. One organization
may have one individual responsible for information risk management (IRM) or a team that works in a
coordinated manner. The overall goal of the team is to ensure the company is protected in the most costeffective manner.
Incorrect Answers:
A: Not all identified risks are mitigated. Some risks are accepted.
C: It is not true that computer security should be first and foremost examined in both monetary and nonmonetary terms.
D: It is not true that computer security should be first and foremost proportionate to the value of IT systems.
The value of IT systems does not necessarily mean that more or less security is required.

Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 87


Leave a Reply