QuestionQ283

Risk Optimization

The CIO of an enterprise discovers that a competitor’s payroll server was the victim of ransomware. To prepare for the possibility that corporate data could be ransomed, what should be the CIO’s FIRST action?

  • A Back up corporate data to a secure location.
  • B Develop a policy to address ransomware.
  • C Require development of key risk indicators (KRIs).
  • D Request a targeted risk assessment.
Explanation

A targeted risk assessment establishes the organization’s ransomware-related threats, vulnerabilities, affected information assets, control gaps, and business impact. Its results provide the basis for selecting and prioritizing safeguards such as secure backups, ransomware policies, and key risk indicators.

Community Discussion

No comments yet. Be the first to start the discussion!