CISSP Practice Question: In a mid-sized financial firm facing budget constraints, which approach BEST balances…
Correct Answer: B. Implement a risk-based approach to security spending
Explanation (CISSP Manager Logic):
A risk-based approach ensures that limited resources are allocated to the areas of greatest potential impact, aligning security costs with business value. This methodology allows management to prioritize investments that mitigate the highest risks while supporting organizational objectives and financial constraints.
By implementing this solution, you:
- Optimize resource allocation based on actual threat exposure.
- Align security expenditures with the organization’s risk appetite.
- Provide a defensible, data-driven rationale for budget requests.
While the other options are relevant, they fall short because:
- A: Compliance is a baseline requirement, but focusing on it exclusively often leaves critical security gaps unaddressed.
- C: Training is a vital administrative control but cannot replace necessary technical and physical safeguards.
- D: Generic solutions fail to account for the firm’s unique risk profile, leading to either over-spending or under-protection.
Think like a manager:
Security is a business enabler, not just a cost center. Always prioritize strategic resource allocation that balances the cost of controls against the potential impact of a realized risk.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial