712-50 Question 272
Single answerDetermine the value of physical assets and the impact if unavailableA newly appointed CISO is preparing next year's security investment plan for a manufacturing company. During a recent regional power incident, the company lost access to its on-premises data center for 10 hours. Production scheduling stopped, warehouse shipping labels could not be generated, and customer service could not view order status. The CFO asks the CISO to justify why the data center and supporting facility equipment should be treated as high-value physical assets rather than valued only at replacement cost. Which approach should the CISO use FIRST to determine the true value of these physical assets and the impact if they become unavailable?
- A
Base the asset value primarily on purchase price, depreciation, and insurance replacement value of the building, servers, and power equipment
- B
Calculate the value by estimating the revenue generated by each IT asset and rank them by original procurement cost
- C
Perform a business impact analysis that maps the physical assets to critical business services, identifies downtime effects, and quantifies operational, financial, legal, and reputational impact
- D
Classify the data center as critical because it hosts security tools and then assign a high value rating based on management judgment
Show answer and explanation
Correct answer: C
Explanation
In CCISO practice, determining the value of physical assets means going beyond accounting value and assessing how asset unavailability affects the enterprise. The most effective starting point is a business impact analysis, which ties physical assets such as data centers, server rooms, power systems, cooling, and communications infrastructure to the business services they support. Best practices from business continuity and information security governance frameworks emphasize evaluating confidentiality, integrity, and especially availability requirements in relation to business objectives. Standards and guidance such as ISO 22301 for business continuity management, ISO/IEC 27005 for information security risk management, and NIST SP 800-34 for contingency planning all support identifying critical functions, dependencies, maximum tolerable downtime, and impact categories. In this scenario, the true value of the physical assets is reflected not just in replacement cost but in the consequences of losing production scheduling, shipping capability, and customer service visibility. A CISO should use that quantified business impact to justify resilience investments such as redundant power, alternate processing capability, improved environmental controls, or facility hardening.
- A. Incorrect.
This is incorrect because replacement cost and depreciation capture only the book or insurable value of the physical assets, not their business value when unavailable. A data center's importance often comes from the business processes it enables. If the organization values only the building, servers, and generators at replacement cost, it will underestimate losses from halted production, delayed shipments, service disruption, contractual penalties, and customer dissatisfaction.
- B. Incorrect.
This is incorrect because original procurement cost is not a reliable indicator of business criticality, and attributing revenue directly to each IT asset is often misleading. Some relatively inexpensive supporting assets, such as power distribution units, cooling systems, or network core devices, can have a disproportionately large operational impact if unavailable. This option reflects a common mistake of confusing cost with criticality.
- C. Correct.
This is correct because a business impact analysis (BIA) is the appropriate first step to determine the value of physical assets in business terms. The CISO should identify which critical services depend on the data center and its supporting facility components, then quantify the effects of downtime across production, logistics, customer operations, regulatory obligations, and brand impact. This approach aligns asset valuation with mission impact and supports risk-based investment decisions.
- D. Incorrect.
This is incorrect because management judgment alone is not sufficient to determine asset value in a defensible, repeatable way. While executive input is useful, simply labeling the data center as critical because it hosts security tools ignores broader business dependencies and does not quantify impact. This can lead to biased prioritization and weak justification for capital or resilience spending.