Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A new Chief Information Security Officer (CISO) is establishing an information security program for a rapidly growing startup. The CISO recognizes the need to align security investments with business objectives. What is the MOST crucial initial step in developing an effective information security program?

  1. APerform a business impact analysis (BIA) to identify critical assets and processes.
  2. BImplement security awareness training for all employees.
  3. CConduct a comprehensive technical vulnerability assessment.
  4. DDevelop a detailed incident response plan.
Show answer & explanation

Correct answer: A. Perform a business impact analysis (BIA) to identify critical assets and processes.

A BIA identifies an organization's critical business functions, processes, and the assets that support them, along with the impact of their disruption. This foundational understanding is essential for aligning security investments with actual business needs and prioritizing protection.

Why the other options are wrong

  • B. Security awareness training is vital but is a control that should be implemented after understanding the core business risks and assets to protect.
  • C. A technical vulnerability assessment is important but should follow the identification of what assets are most critical to the business.
  • D. An incident response plan is a critical component but cannot be effectively developed without first understanding the most critical business processes and assets.

Business Impact Analysis (BIA)

A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.

  • Identifies critical business functions and processes.
  • Determines recovery time objectives (RTO) and recovery point objectives (RPO).
  • Essential for prioritizing security controls and resilience efforts.

Memory trick: BIA builds the security foundation.

More Information Security Risk Management questions