CAS-003 · Question #424
A Chief Information Security Officer (CISO) is reviewing the controls in place to support the organization's vulnerability management program. The CISO finds patching and vulnerability scanning…
The correct answer is D. Threat awareness. The CISO's concern is that the organization is siloed and not maintaining awareness of new and emerging risks. Sending systems administrators to industry security events (conferences, ISACs, threat intelligence sharing groups) directly improves their knowledge of current and…
Question
A Chief Information Security Officer (CISO) is reviewing the controls in place to support the organization's vulnerability management program. The CISO finds patching and vulnerability scanning policies and procedures are in place. However, the CISO is concerned the organization is siloed and is not maintaining awareness of new risks to the organization. The CISO determines systems administrators need to participate in industry security events. Which of the following is the CISO looking to improve?
Options
- AVendor diversification
- BSystem hardening standards
- CBounty programs
- DThreat awareness
- EVulnerability signatures
How the community answered
(45 responses)- A2% (1)
- D93% (42)
- E4% (2)
Explanation
The CISO's concern is that the organization is siloed and not maintaining awareness of new and emerging risks. Sending systems administrators to industry security events (conferences, ISACs, threat intelligence sharing groups) directly improves their knowledge of current and evolving threats. This is the definition of improving 'Threat Awareness.' The other options are unrelated: vendor diversification addresses supply chain risk, system hardening standards address configuration, bounty programs address internal vulnerability discovery, and vulnerability signatures are about detection tool updates - none address the awareness gap caused by organizational isolation.
Topics
Community Discussion
No community discussion yet for this question.