Justifying Security Investments for Critical Applications
Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?
Community Votes
75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests executive communication and business alignment, with the common trap being the selection of risk tolerance over measurable ROI.
This CISM scenario evaluates how to effectively pitch security controls to executives. Community consensus emphasizes that financial justification outweighs compliance or anecdotal triggers.
Option D is frequently selected because it sounds governance-aligned, but simply meeting risk tolerance does not inherently justify the capital expenditure required for new infrastructure.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Senior management approves budgets based on tangible business value and financial protection. Demonstrating that implementation costs are lower than the potential financial impact of downtime directly ties the security control to organizational resilience and ROI. This aligns with ISACA’s emphasis on framing security initiatives as business enablers rather than pure technical requirements.Why the Other Options Are Wrong
Option A focuses on scalability, which is secondary to immediate risk mitigation for a critical asset. Option B relies on external events that do not account for internal probability or specific business impact. Option D describes an acceptable risk state rather than a proactive investment trigger, making it insufficient for securing new funding.Community Comment Notes
Users consistently validate option C by highlighting that companies fund projects when they see clear financial returns [Comment 1]. One top comment notes that risk tolerance alone rarely motivates spending, whereas a direct cost-versus-loss comparison provides the executive urgency needed for approval [Comment 4]. Another user points out that probability should be factored into the impact calculation, reinforcing the need for quantitative risk assessment [Comment 3].Official Reference
Exam Strategy
Always translate technical security needs into financial or operational business terms when targeting executive audiences. Quantify risks using Annualized Loss Expectancy (ALE) or comparable cost-benefit metrics to make the business case undeniable.
Frequently Asked Questions
Why is risk tolerance (D) not enough to justify a new monitoring system?
Risk tolerance only defines acceptable loss levels; it does not provide the financial rationale or ROI required to approve new budget allocations.
How should I calculate impact for a critical application business case?
Use quantitative methods like Annualized Loss Expectancy (ALE) to compare projected downtime costs against control implementation expenses.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →