QuestionQ657

Information Security Risk Management

Which of the following provides the MOST guidance when determining the appropriate level of protection for an information asset?

  • A Impact on information security program
  • B Cost of controls
  • C Impact to business function
  • D Cost to replace
Explanation

An information asset’s protection requirements are based primarily on the impact that its loss of confidentiality, integrity, or availability would have on the business function it supports. This business impact determines the appropriate classification and level of safeguards.

Community Discussion

No comments yet. Be the first to start the discussion!