QuestionQ1896

Risk Response and Reporting

An information security manager has recommended purchasing a data loss prevention (DLP) system to lessen the impact of a possible data breach. Which of the following is the BEST way for the risk practitioner to support this recommendation?

  • A Map the DLP system to existing risk scenarios
  • B Assign an IT owner for the DLP system
  • C Quantify the costs of the risk mitigation effort
  • D Determine the likelihood of potential loss
Explanation

A DLP system is a risk-mitigation control. Mapping it to existing risk scenarios establishes the direct relationship between the control and the identified breach risks it is intended to reduce, supporting risk-based treatment and prioritization. ISACA identifies DLP as an example of a risk-mitigation measure and describes controls as linked to risk scenarios in the risk register.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!