QuestionQ305

Information Security Risk Management

To manage an organization’s information security risk effectively, it is MOST important to:

  • A establish and communicate risk tolerance.
  • B benchmark risk scenarios against peer organizations.
  • C assign risk management responsibility to an experienced consultant.
  • D periodically identify and correct new systems vulnerabilities.
Explanation

Establishing and communicating risk tolerance gives the organization a common, leadership-approved basis for evaluating risks and deciding which risks to accept, mitigate, transfer, or avoid. This guides all other risk-management activities.

Community Discussion

No comments yet. Be the first to start the discussion!