QuestionQ528
Information Security Risk ManagementAn information security manager has just been notified about possible security risks involving a third-party service provider. What should be done NEXT to address this concern?
- A Escalate to the chief risk officer (CRO).
- B Conduct a vulnerability analysis.
- C Conduct a risk analysis.
- D Determine compensating controls.
Community Discussion