QuestionQ119
Information Security ManagementA capability assessment determines that an organization has comprehensive security policies and plans. It is highly effective at identifying security risks and managing them through effective controls. The effectiveness of information security controls is monitored and reported. The reports indicate that the controls are effective, so the team sees no reason to review or modify the policies or controls.
What capability level should this assessment report?
- A Level 4
- B Level 3
- C Level 5
- D Level 2
Community Discussion