Prior to performing an enterprise risk analysis, the security professional MUST first:
A.
Identify the threats
B.
Identify the assets to be protected
C.
Classify all risks
D.
Determine if adequate security exists
The Answer Is:
B
This question includes an explanation.
Explanation:
Before an enterprise risk analysis can be properly conducted, the security professional must first identify the assets to be protected. These may include people, property, information, and operations. Only after defining what needs protection can threats, vulnerabilities, and risks be effectively evaluated.
A (Identify threats) comes after asset identification.
C (Classify risks) and D (Determine security adequacy) are later stages in the risk management process.
[References:, PSP Study Guide – Enterprise Risk Management Process, POA Manual – Asset Identification and Risk Assessment]
ASIS-PSP PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"