When Should Risk Assessment Occur Before a Business Case?
When considering a new security initiative, which of the following should be done prior to the development of a business case?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the proper sequence in security governance: understanding organizational risk must precede justifying investments through a business case.
Developing a business case for a security initiative requires first conducting a risk assessment to justify the need. The CISM community consensus confirms that risk assessment precedes business case development.
Cost-benefit analysis (C) is frequently chosen incorrectly because candidates confuse a required component of the business case with a prerequisite step.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In CISM methodology, a risk assessment must precede business case development because it identifies existing threats, vulnerabilities, and potential business impacts. This foundational data justifies why the security initiative is necessary and aligns it with organizational risk appetite. As noted in community feedback, the risk assessment provides the essential evidence and context needed to build a solid, risk-aligned business case. Without this step, any proposed initiative lacks strategic justification.Why the Other Options Are Wrong
Cost-benefit analysis (C) is a core component of the business case itself, not a precursor; attempting it beforehand creates circular logic without knowing the underlying risks. Benchmarking exercises (B) help select appropriate controls but occur after the initiative's necessity is established. Identifying resource requirements (D) belongs to project planning and budgeting, which only happens once the business case secures executive approval.Community Comment Notes
Several candidates debated between risk assessment and cost-benefit analysis, highlighting a common sequencing confusion. Commenters correctly pointed out that cost-benefit calculations depend entirely on quantified risk data derived from the initial assessment. Others emphasized that ISACA explicitly structures governance workflows to move from risk identification to business justification, reinforcing option A as the definitive first step.Official Reference
Exam Strategy
Always follow ISACA’s governance lifecycle when sequencing tasks: assess risk before justifying investment. Financial evaluations like cost-benefit analysis belong inside the business case, not before it.
Frequently Asked Questions
Why isn't cost-benefit analysis done first?
It is a core component of the business case itself, not a prerequisite. You need risk data first to calculate meaningful benefits.
How does benchmarking fit into the timeline?
Benchmarking informs control selection and planning, occurring after the business case is approved or during detailed implementation.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →