Identifying Emerging Technology Threats
Which of the following BEST enables an information security manager to identify changes in the threat landscape due to emerging technologies?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the understanding that a formal risk assessment process is the primary mechanism for managers to detect environmental changes, rather than relying on ad-hoc external advice.
Identifying changes in the threat landscape due to emerging technologies is best achieved through periodic risk assessments. Community consensus favors this systematic process over relying solely on external expert input.
Choosing A (Input from external experts) is a common error because emerging technologies imply a need for specialized knowledge, but CISM prioritizes the manager's internal assessment process.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Periodic risk assessments are the foundational tool for an information security manager to identify and evaluate changes in the threat landscape. This process forces a regular review of assets, threats, and vulnerabilities, ensuring that risks from emerging technologies are systematically identified and quantified within the organization's context. It aligns with the CISM principle that risk management is a continuous, structured activity.Why the Other Options Are Wrong
Input from external experts (Option A) provides valuable intelligence but is a data source rather than a management process. Annual security assessments (Option B) are too infrequent to keep pace with emerging technologies. Benchmarking against industry peers (Option D) offers comparison points but does not directly identify specific changes in the organization's unique threat landscape.Community Comment Notes
There is a notable split in the community, with 67% of votes supporting Option C. While some commenters argued for Option A due to the specialized nature of emerging technologies, the majority and the most-liked comments (accumulating 6 likes vs 3 for A) reinforce that the risk assessment process is the manager's primary responsibility.Official Reference
Exam Strategy
When questions ask about identifying changes in the environment or threats, prioritize the systematic process (Risk Assessment) over specific data sources (Experts). The manager's role is to own the process.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →