QuestionQ481

Information Security Risk Management

In an organization operating in a rapidly changing environment, business management has accepted an information security risk. It is MOST important for the information security manager to ensure:

  • A change activities are documented.
  • B compliance with the risk acceptance framework.
  • C the rationale for acceptance is periodically reviewed.
  • D the acceptance is aligned with business strategy.
Explanation

Accepted risk must be reassessed when the environment changes because the threats, vulnerabilities, likelihood, impact, and business context underlying the acceptance may no longer be valid. Periodically reviewing the acceptance rationale confirms that management’s decision remains appropriate or identifies when the risk needs a different treatment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!