CGEIT · Question #245
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but…
The correct answer is B. Risk register. To make the best decision for customers when facing time-to-market pressure with unresolved security issues involving sensitive data, the CIO should review the risk register. This document provides a clear overview of identified security risks, their potential impacts, and…
Question
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
Options
- AAcceptable use policy
- BRisk register
- CEthics standards
- DChange ma agement policy
How the community answered
(30 responses)- A10% (3)
- B57% (17)
- C27% (8)
- D7% (2)
Why each option
To make the best decision for customers when facing time-to-market pressure with unresolved security issues involving sensitive data, the CIO should review the risk register. This document provides a clear overview of identified security risks, their potential impacts, and proposed mitigation strategies, enabling an informed risk-based decision.
An acceptable use policy defines how users can utilize IT resources, which is not directly relevant to addressing unmitigated security scan results on a new service.
Reviewing the risk register will enable the CIO to make the best decision because it centralizes all identified security vulnerabilities, their potential impacts on sensitive personal data, likelihoods, and existing mitigation plans. This allows the CIO to understand the actual exposure to customers, weigh the risks against the pressure to go to market, and make a data-driven decision regarding customer protection and organizational liability.
Ethics standards guide behavior, but don't provide the specific technical details of identified security flaws or their impact, nor a framework for risk prioritization and mitigation.
A change management policy outlines procedures for managing changes to IT systems, but it doesn't detail the specific security risks or their implications for the new services.
Concept tested: Risk-Based Decision Making
Topics
Community Discussion
No community discussion yet for this question.