QuestionQ115

Cybersecurity Principles and Risks

Which of the following should be considered first when establishing an application-security risk metric for an organization?

  • A Alignment with the system development life cycle (SDLC)
  • B Criticality of application data
  • C Creation of risk reporting templates
  • D Identification of application dependencies
Explanation

Application data criticality establishes the potential business impact of a security incident, making it a core basis for prioritizing and scoring application security risk. More sensitive or business-critical data generally warrants a higher risk rating when exposed or compromised.

Community Discussion

No comments yet. Be the first to start the discussion!