QuestionQ528

Information Security Risk Management

An information security manager has just been notified about possible security risks involving a third-party service provider. What should be done NEXT to address this concern?

  • A Escalate to the chief risk officer (CRO).
  • B Conduct a vulnerability analysis.
  • C Conduct a risk analysis.
  • D Determine compensating controls.
Explanation

A risk analysis evaluates the likelihood and business impact of the identified third-party security risks, providing the basis for risk treatment decisions, escalation, or selection of compensating controls.

Community Discussion

No comments yet. Be the first to start the discussion!