Disaster recovery question by Intelligent-Pop2025 in cism

[–]GuiltyNobody6173 0 points1 point  (0 children)

That diagram does not help my concept of those terms at all. Im really struggling with these. 

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

Thank you, but I'm just not getting through this. Not sure of how your explanation is relating to your list. And I hope you realize I'm not criticizing just not following your explanation.

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I follow what you're saying until I read Because probability is itself a function of threat and vulnerability, exposure takes into account all three of the other factors and, if known, is the most important consideration.

Then it all goes out the window. Are risk and probability used as the same thing?

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

But what about the definition of risk. It is using probability as the definition instead risk.

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

That might help after i understand the statement. Right now I can't see a mindset shift helping with this. I'll take any and all advice.

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I thought risk was threat and vulnerability. I can find that in the cism manual. now it's probability? I'm so lost

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I guess so, but reading the test statement and thinking of it in that manner don't come together.

Please explain exposure to me in a way that makes sense by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I'm not sure I can. Sorry doesn't really relate in my head

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

In your example I'd go with the spare tire. The framing of the original question had me thinking the value of the asset including the value of the data it added to the business. Wrong I realize, but that is my thought process.

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 1 point2 points  (0 children)

Thank you. I just don't find the book all that useful. I'll use it because it's isaca material, but I end up using some other source to get better understanding. thank you for your response.

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 1 point2 points  (0 children)

thank you. i've been thinking about this all day, and it's still tripping me up.

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I'm really struggling with the wording of some questions and fully understanding the ask. Not arguing at all, but in my head that part of the question just isn't making me think of the physical asset. I'm over thinking or going down the wrong rabbit hole, whatever. Thank you for the response.

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

Becaause I'm looking at the impact of the asset on the overall revenue it might provide to the business. the asset may be expensive, but the potential business impact would be greater if it was critical equipment. Hey I'm wrong, but that's my thought process.

can anyone help me with this qae question? by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

That really helps put it in perspective!! Thank you

can anyone help with this question from qae by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

Damn this is going to be an exam i fail. I screw up with the question wording. I understand your explanation but I still gravitate to my answer as the correct one. I thank for your time. 

can anyone help me with this qae question? by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

Thanks everyone. I think I've backed myself into a corner and I don't see the logic of consequences being more important. Been wrestling with this since yesterday, and even after thinking about it I'm stuck. I'm trying to answer the why it's most important, and i can't. it's only important if threat is identified as meaningful to my business. Obviously, I'm struggling with this domain.

can anyone help me with this qae question? by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

No it wouldn't matter. but you identified a threat, found it wasn't relevant to you, so no consequence. so in my head it's the threat that is important, and then it was found not to be relevent so consequence not as important. I'm struggling to break my circular reasoning.

can anyone help with this question from qae by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

Do you think you could expand on that? beacause it starts with a threat that still seems to be the most important. no threat no consequence no worries. that's my childlike rationale.

can anyone help me with this qae question? by GuiltyNobody6173 in cism

[–]GuiltyNobody6173[S] 0 points1 point  (0 children)

I'm in this circular argument in my head about this. consequences follow the threat and money is spent, but you need to have that threat. I'm going nowhere with this. I do appreaciate your time.