QuestionQ42

Information Security Risk Management

An organization’s cloud application is discovered to contain a serious vulnerability. After evaluating the risk, which of the following is the information security manager’s BEST course of action?

  • A Instruct the vendor to conduct penetration testing.
  • B Suspend the connection to the application in the firewall.
  • C Initiate the organization’s incident response process.
  • D Report the situation to the business owner of the application.
Explanation

The business owner is responsible for accepting and directing treatment of the application’s business risk. Reporting the assessed vulnerability enables an authorized decision on remediation, compensating controls, risk acceptance, or operational interruption. A vulnerability alone does not necessarily require incident response or an immediate service shutdown.

Community Discussion

No comments yet. Be the first to start the discussion!