QuestionQ1092

Information Security Risk Management

Which approach is BEST for an information security manager when choosing cost-effective controls required to achieve business objectives?

  • A Conduct a gap analysis.
  • B Focus on preventive controls.
  • C Align with industry best practice.
  • D Align with the risk appetite.
Explanation

Security controls should be selected and funded according to the organization’s risk appetite, so that residual risk is reduced to an acceptable level without spending beyond what is justified by business objectives.

Community Discussion

No comments yet. Be the first to start the discussion!