Identifying Emerging Technology Threats

Risk Management
Answer Correct answer: C — Conduct periodic risk assessments to identify changes in the threat landscape.

Which of the following BEST enables an information security manager to identify changes in the threat landscape due to emerging technologies?

  1. Input from external experts
  2. Annual security assessments
  3. Periodic risk assessments Correct Answer
  4. Benchmarking against industry peers

Community Votes

C
67%
A
33%

67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the understanding that a formal risk assessment process is the primary mechanism for managers to detect environmental changes, rather than relying on ad-hoc external advice.

Identifying changes in the threat landscape due to emerging technologies is best achieved through periodic risk assessments. Community consensus favors this systematic process over relying solely on external expert input.

Choosing A (Input from external experts) is a common error because emerging technologies imply a need for specialized knowledge, but CISM prioritizes the manager's internal assessment process.

Community Discussion (4 comments)

Der_Phomas 👍 1 Selected: A
Threat Landscape are the keywords - so external experts are the BEST way
ServerBrain 👍 2 Selected: C
C. Periodic risk assessments
koala_lay 👍 2 Selected: A
A. Input from external experts is the best way for an information security manager to identify changes in the threat landscape due to emerging technologies. External experts, such as cybersecurity researchers, industry analysts, and threat intelligence providers, have a broader and more up-to-date understanding of the evolving threat landscape, including the impact of new technologies. Annual security assessments and Periodic risk assessments are important, but they are more focused on the organization's current security posture and may not capture the rapidly changing threat landscape driven by emerging technologies.
bronay 👍 4 Selected: C
C risk assessment

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Periodic risk assessments are the foundational tool for an information security manager to identify and evaluate changes in the threat landscape. This process forces a regular review of assets, threats, and vulnerabilities, ensuring that risks from emerging technologies are systematically identified and quantified within the organization's context. It aligns with the CISM principle that risk management is a continuous, structured activity.

Why the Other Options Are Wrong

Input from external experts (Option A) provides valuable intelligence but is a data source rather than a management process. Annual security assessments (Option B) are too infrequent to keep pace with emerging technologies. Benchmarking against industry peers (Option D) offers comparison points but does not directly identify specific changes in the organization's unique threat landscape.

Community Comment Notes

There is a notable split in the community, with 67% of votes supporting Option C. While some commenters argued for Option A due to the specialized nature of emerging technologies, the majority and the most-liked comments (accumulating 6 likes vs 3 for A) reinforce that the risk assessment process is the manager's primary responsibility.

Official Reference

Exam Strategy

When questions ask about identifying changes in the environment or threats, prioritize the systematic process (Risk Assessment) over specific data sources (Experts). The manager's role is to own the process.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide