QuestionQ145

Information Security Risk Management

Regular vulnerability scans of an organization’s internal network have found that many user workstations are running unpatched software versions. What is the BEST way for the information security manager to help senior management understand the associated risk?

  • A Include the impact of the risk as part of regular metrics.
  • B Send regular notifications directly to senior managers.
  • C Recommend the security steering committee conduct a review.
  • D Update the risk assessment at regular intervals.
Explanation

Regular metrics that state the potential impact of unpatched software provide senior management with an ongoing, business-relevant view of the risk. This turns a technical vulnerability finding into information that supports risk awareness and management decisions.

Community Discussion

No comments yet. Be the first to start the discussion!