QuestionQ1009

Information Security Risk Management

An information security team intends to strengthen password-complexity requirements for a customer-facing site, but there are concerns that this could adversely affect the user experience. What is the information security manager's BEST course of action?

  • A Evaluate business compensating controls.
  • B Quantify the security risk to the business.
  • C Assess business impact against security risk.
  • D Conduct industry benchmarking.
Explanation

Security requirements should be selected by weighing their risk reduction against their business impact, including effects on customer usability. This enables a proportionate control decision that aligns security with business objectives.

Community Discussion

No comments yet. Be the first to start the discussion!