EC-Council
512-50 · Question #295
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines…
The correct answer is B. Validate gaps and accept or dispute the audit findings. See the full explanation below for the reasoning.
Question
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified. Which of the following is the FIRST action the CISO will perform after receiving the audit report?
Options
- AInform peer executives of the audit results
- BValidate gaps and accept or dispute the audit findings
- CCreate remediation plans to address program gaps
- DDetermine if security policies and procedures are adequate
How the community answered
(41 responses)- A7% (3)
- B76% (31)
- C15% (6)
- D2% (1)
Community Discussion
No community discussion yet for this question.