QuestionQ85

Cybersecurity Principles and Risks

Which of the following should be considered FIRST when deciding how to protect an organization’s information assets?

  • A The organization's risk reporting
  • B Results of vulnerability assessments
  • C The organization's business model
  • D A prioritized inventory of IT assets
Explanation

An organization’s business model establishes its objectives, critical operations, and the value of its information assets. Protection requirements, risk priorities, vulnerability remediation, and asset prioritization should align with that business context.

Community Discussion

No comments yet. Be the first to start the discussion!