QuestionQ628

Information Security Risk Management

What is an information security manager’s BEST course of action when a threat intelligence report shows a large number of ransomware attacks targeting the industry?

  • A Assess the risk to the organization.
  • B Review the mitigating security controls.
  • C Notify staff members of the threat.
  • D Increase the frequency of system backups.
Explanation

An organization-specific risk assessment evaluates the relevant threat in the context of the organization’s assets, vulnerabilities, existing controls, likelihood, and potential impact. Its results provide the basis for selecting and prioritizing responses such as control reviews, staff communications, or backup changes.

Community Discussion

No comments yet. Be the first to start the discussion!