A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?
Risk assessment begins with identifying and classifying the information assets the cloud system will hold, since sensitivity and value drive every subsequent threat, vulnerability, and impact analysis. Without an asset inventory, later likelihood and impact ratings lack a defensible basis.
Why this answer
In the risk assessment process, the first step is to identify and classify information assets because you cannot assess risks to assets you haven't identified. For a cloud-based system storing sensitive customer data, this means cataloging data types (e.g., PII, financial records), their locations (e.g., specific cloud storage buckets), and their classification levels (e.g., confidential, restricted) before any threat or vulnerability analysis can be meaningfully performed.
Exam trap
The trap here is that candidates often confuse the order of risk assessment steps, mistakenly thinking that identifying threats (Option C) comes first because threats are the 'active' element, but CISM emphasizes that asset identification is the foundational step that drives all subsequent analysis.
How to eliminate wrong answers
Option A is wrong because selecting security controls is a risk treatment step that occurs after risks have been assessed and prioritized, not at the beginning of the assessment. Option B is wrong because vulnerability scanning is a technical activity that identifies weaknesses in existing systems, but it cannot be effectively scoped or targeted without first knowing which assets are in scope and their classification. Option C is wrong because while identifying threat sources is important, it logically follows asset identification; you must know what assets you are protecting before you can determine which threats are relevant to those specific assets.