CAS-003 · Question #445
An information security manager conducted a gap analysis, which revealed a 75% implementation of security controls for high-risk vulnerabilities, 90% for medium vulnerabilities, and 10% for low-risk…
The correct answer is D. BIA. – BIA (business impact analysis) A document that identifies present organizational risks and determines the impact to ongoing, business critical operations if such risks actualize. – GRC (governance, risk management, and compliance) A solution for monitoring these three…
Question
An information security manager conducted a gap analysis, which revealed a 75% implementation of security controls for high-risk vulnerabilities, 90% for medium vulnerabilities, and 10% for low-risk vulnerabilities. To create a road map to close the identified gaps, the assurance team reviewed the likelihood of exploitation of each vulnerability and the business impact of each associated control. To determine which controls to implement, which of the following is the MOST important to consider?
Options
- AKPI
- BKRI
- CGRC
- DBIA
How the community answered
(24 responses)- A4% (1)
- B21% (5)
- C8% (2)
- D67% (16)
Explanation
– BIA (business impact analysis) A document that identifies present organizational risks and determines the impact to ongoing, business critical operations if such risks actualize. – GRC (governance, risk management, and compliance) A solution for monitoring these three security concepts as they are implemented in an enterprise.
Topics
Community Discussion
No community discussion yet for this question.