Certified Information Security Manager (CISM)Information Security GovernanceHard
A multinational corporation is acquiring a smaller technology startup. The CISO of the acquiring company initiates a due diligence process related to information security. Which of the following is the MOST critical initial step for the CISO to undertake?
- AConducting penetration testing on the startup's external-facing systems.
- BEvaluating the startup's information assets and their criticality to the acquiring company's operations.
- CReviewing the startup's existing security policies and procedures for gaps.
- DAssessing the startup's compliance with relevant data protection regulations.
Show answer & explanationAnswer & explanation
Correct answer: B. Evaluating the startup's information assets and their criticality to the acquiring company's operations.
The most critical initial step in information security due diligence during an acquisition is to evaluate the startup's information assets and their criticality. This determines the scope and priority of subsequent security assessments by identifying what needs to be protected and its value to the acquiring entity.
Why the other options are wrong
- A. Penetration testing is a technical assessment that comes later, after understanding the asset landscape and overall risk profile.
- C. Reviewing policies is important but follows understanding what assets are at stake and their value.
- D. Assessing compliance is crucial but depends on knowing which assets are subject to which regulations and their criticality.
M&A Security Due Diligence
The process of thoroughly investigating and evaluating the information security posture, risks, and liabilities of a target company during a merger or acquisition.
- Identifies security risks before integration.
- Protects the acquiring company from inheriting vulnerabilities.
- Ensures compliance and data integrity post-acquisition.
Memory trick: Before you buy, identify the crown jewels you're getting and how shiny they are.