QuestionQ282
Information Security Risk ManagementAn organization’s primary product is a customer-facing application provided through Software as a Service (SaaS). The lead security engineer has just discovered a major security vulnerability at the primary cloud provider. Who within the organization is PRIMARILY accountable for the related risk?
- A The data owner
- B The information security manager
- C The security engineer
- D The application owner
Community Discussion