
Which one of the following risk management tasks should be done first? (Wentz QOTD)
A. Identify risks
B. Conduct risk assessment
C. Establish a shared glossary
D. Determine risk exposure
Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.
My suggested answer is C. Establish a shared glossary.
Wentz’s book, The Effective CISSP: Security and Risk Management, helps CISSP and CISM aspirants build a solid conceptual security model. It is a tutorial for information security and a supplement to the official study guides for the CISSP and CISM exams and an informative reference for security professionals.

Before diving into risk management processes, we must establish the scope, context, criteria, etc. A shared glossary is crucial for effective risk management. Suppose we use risk terms without agreed definitions, such as risk appetite, risk capacity, risk tolerance, risk threshold, risk analysis, risk assessment, risk evaluation, etc. In that case, we can expect an ineffective outcome.


Reference
下列哪一項風險管理任務應該首先完成? (Wentz QOTD)
A. 識別風險
B. 進行風險評鑑
C. 建立共享詞彙表
D. 確定風險敞口
A
A