Justifying Security Investments for Critical Applications

Security Governance & Risk Management
Answer Correct answer: C — Present a cost-benefit analysis showing implementation expenses fall below potential downtime losses to secure executive funding.

Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?

  1. The system can be replicated for additional use cases.
  2. An industry peer experienced a recent breach with a similar application.
  3. The cost of implementing the system is less than the impact of downtime. Correct Answer
  4. The solution is within the organization's risk tolerance.

Community Votes

C
75%
D
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests executive communication and business alignment, with the common trap being the selection of risk tolerance over measurable ROI.

This CISM scenario evaluates how to effectively pitch security controls to executives. Community consensus emphasizes that financial justification outweighs compliance or anecdotal triggers.

Option D is frequently selected because it sounds governance-aligned, but simply meeting risk tolerance does not inherently justify the capital expenditure required for new infrastructure.

Community Discussion (4 comments)

david124 👍 3 Selected: C
c all the way, d is more of a risk assessment , just because you can tolerate a solution, dont mean its free. it costs money, no company will spend money on a solution because they can "tolerate" it. C on the other hands is telling you hey, this app would cost us 10 dollars if breached, but it only costs 2 dollars to mitigate it. just my two cents
ServerBrain 👍 1 Selected: D
D. The solution is within the organization's risk tolerance.
bronay 👍 3 Selected: C
C. Cost
RunAmok113 👍 1 Selected: D
C doesn't take into consideration probability.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Senior management approves budgets based on tangible business value and financial protection. Demonstrating that implementation costs are lower than the potential financial impact of downtime directly ties the security control to organizational resilience and ROI. This aligns with ISACA’s emphasis on framing security initiatives as business enablers rather than pure technical requirements.

Why the Other Options Are Wrong

Option A focuses on scalability, which is secondary to immediate risk mitigation for a critical asset. Option B relies on external events that do not account for internal probability or specific business impact. Option D describes an acceptable risk state rather than a proactive investment trigger, making it insufficient for securing new funding.

Community Comment Notes

Users consistently validate option C by highlighting that companies fund projects when they see clear financial returns [Comment 1]. One top comment notes that risk tolerance alone rarely motivates spending, whereas a direct cost-versus-loss comparison provides the executive urgency needed for approval [Comment 4]. Another user points out that probability should be factored into the impact calculation, reinforcing the need for quantitative risk assessment [Comment 3].

Official Reference

Exam Strategy

Always translate technical security needs into financial or operational business terms when targeting executive audiences. Quantify risks using Annualized Loss Expectancy (ALE) or comparable cost-benefit metrics to make the business case undeniable.

Frequently Asked Questions

Why is risk tolerance (D) not enough to justify a new monitoring system?

Risk tolerance only defines acceptable loss levels; it does not provide the financial rationale or ROI required to approve new budget allocations.

How should I calculate impact for a critical application business case?

Use quantitative methods like Annualized Loss Expectancy (ALE) to compare projected downtime costs against control implementation expenses.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide