QuestionQ53

Information Security Risk Management

For an information security manager, it is MOST important to ensure that security risk assessments are conducted:

  • A during a root cause analysis.
  • B as part of the security business case.
  • C consistently throughout the enterprise.
  • D in response to the threat landscape.
Explanation

Security risk assessments must be conducted consistently throughout the enterprise to provide comprehensive, uniform identification and treatment of information-security risks across all relevant business processes, systems, and units.

Community Discussion

No comments yet. Be the first to start the discussion!