QuestionQ991

Information Security Risk Management

Risk reevaluation is MOST critical when there is:

  • A a management request for updated security reports.
  • B resistance to the implementation of mitigating controls.
  • C a change in the threat landscape.
  • D a change in security policy.
Explanation

A change in the threat landscape can change the likelihood and potential impact of adverse events, so the assessed risk level and the adequacy of existing controls may no longer be valid.

Community Discussion

No comments yet. Be the first to start the discussion!