CAS-002 · Question #26
The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase…
The correct answer is C. Work with the business to understand and classify the risk associated with the full lifecycle. Since management has overridden the security manager's objections, the best course is to formally evaluate and document the risk across the entire asset lifecycle-from procurement and deployment through use and eventual disposal. This lifecycle risk analysis identifies threats…
Question
The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase productivity. This includes the development of a new product tracking application that works with the new platform. The security manager attempted to stop the deployment because the equipment and application are non-standard and unsupported within the organization. However, upper management decided to continue the deployment. Which of the following provides the BEST method for evaluating the potential threats?
Options
- AConduct a vulnerability assessment to determine the security posture of the new devices
- BBenchmark other organization's that already encountered this type of situation and apply all
- CWork with the business to understand and classify the risk associated with the full lifecycle
- DDevelop a standard image for the new devices and migrate to a web application to eliminate
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C77% (27)
- D6% (2)
Explanation
Since management has overridden the security manager's objections, the best course is to formally evaluate and document the risk across the entire asset lifecycle-from procurement and deployment through use and eventual disposal. This lifecycle risk analysis identifies threats at each stage, helps the business make informed risk decisions, and creates accountability. A vulnerability assessment (A) is a point-in-time technical scan and doesn't capture ongoing lifecycle risks or business context. Benchmarking other organizations (B) may provide useful reference points but doesn't account for this organization's specific environment, data sensitivity, or risk tolerance. Developing a standard image (D) is a remediation action, not an evaluation of potential threats.
Topics
Community Discussion
No community discussion yet for this question.