When Should Risk Assessment Occur Before a Business Case?

Information Security Governance
Answer Correct answer: A — Conduct a risk assessment to quantify organizational threats before building the financial justification.

When considering a new security initiative, which of the following should be done prior to the development of a business case?

  1. Conduct a risk assessment Correct Answer
  2. Conduct a benchmarking exercise
  3. Perform a cost-benefit analysis
  4. Identify resource requirements

Community Votes

A
67%
C
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the proper sequence in security governance: understanding organizational risk must precede justifying investments through a business case.

Developing a business case for a security initiative requires first conducting a risk assessment to justify the need. The CISM community consensus confirms that risk assessment precedes business case development.

Cost-benefit analysis (C) is frequently chosen incorrectly because candidates confuse a required component of the business case with a prerequisite step.

Community Discussion (5 comments)

SHERLOCKAWS 👍 1 Selected: A
Answer is A: Because it provides the evidence and context needed to build a solid, risk-aligned business case for any new security initiative. cost benefit analysis is in the business case.
Pichon 👍 2 Selected: A
1 step is a risk assessment; then on the business case, you need to do a risk cost analysis after you analyze the risks.
PluDou_111 👍 1 Selected: A
RA, The correct answer is: A. Conduct a risk assessment Explanation: Before developing a business case for a new security initiative, a risk assessment should be conducted to identify potential threats, vulnerabilities, and the impact on the organization. This helps in determining whether the initiative is necessary and aligns with the organization’s risk management strategy. • B. Conduct a benchmarking exercise – This can provide useful insights but is typically done after understanding the organization’s specific risks. • C. Perform a cost-benefit analysis – This is part of the business case development and comes after identifying risks and determining the need for the initiative. • D. Identify resource requirements – This is a later step after establishing the justification for the initiative. By conducting a risk assessment first, the organization ensures that the security initiative is driven by actual business and security needs rather than assumptions.
Josef4CISM 👍 3 Selected: C
My take is: A security initiative is the result of a risk assessment. E.g., the security initiative could mean the implementation of a SIEM as a mitigating control. Therefore, a risk assessment is given already. To decide whether certain controls should be implemented, a cost-benefit analysis must be done. If costs outweigh benefits, there is no need to write a business case. If benefits outweigh costs, the cost-benefit analysis will be part of the business case later on.
ServerBrain 👍 2 Selected: A
A. Conduct a risk assessment

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In CISM methodology, a risk assessment must precede business case development because it identifies existing threats, vulnerabilities, and potential business impacts. This foundational data justifies why the security initiative is necessary and aligns it with organizational risk appetite. As noted in community feedback, the risk assessment provides the essential evidence and context needed to build a solid, risk-aligned business case. Without this step, any proposed initiative lacks strategic justification.

Why the Other Options Are Wrong

Cost-benefit analysis (C) is a core component of the business case itself, not a precursor; attempting it beforehand creates circular logic without knowing the underlying risks. Benchmarking exercises (B) help select appropriate controls but occur after the initiative's necessity is established. Identifying resource requirements (D) belongs to project planning and budgeting, which only happens once the business case secures executive approval.

Community Comment Notes

Several candidates debated between risk assessment and cost-benefit analysis, highlighting a common sequencing confusion. Commenters correctly pointed out that cost-benefit calculations depend entirely on quantified risk data derived from the initial assessment. Others emphasized that ISACA explicitly structures governance workflows to move from risk identification to business justification, reinforcing option A as the definitive first step.

Official Reference

Exam Strategy

Always follow ISACA’s governance lifecycle when sequencing tasks: assess risk before justifying investment. Financial evaluations like cost-benefit analysis belong inside the business case, not before it.

Frequently Asked Questions

Why isn't cost-benefit analysis done first?

It is a core component of the business case itself, not a prerequisite. You need risk data first to calculate meaningful benefits.

How does benchmarking fit into the timeline?

Benchmarking informs control selection and planning, occurring after the business case is approved or during detailed implementation.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide