CGEIT · Question #264
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT
The correct answer is B. Request an IT security assessment to identify the main security gaps.. When experiencing numerous security incidents, the IT governance board's first action should be to understand the root causes by identifying current security gaps.
Question
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
Options
- ARequire revisions to how security incidents are managed by the IT department.
- BRequest an IT security assessment to identify the main security gaps.
- CExecute an IT maturity assessment of the security process.
- DMandate an update to the enterprise's IT security policy.
How the community answered
(46 responses)- A22% (10)
- B63% (29)
- C4% (2)
- D11% (5)
Why each option
When experiencing numerous security incidents, the IT governance board's first action should be to understand the root causes by identifying current security gaps.
Revising incident management without understanding the underlying security gaps might address symptoms but not the root cause, leading to continued incidents.
Before prescribing solutions or updating policies, it is crucial to understand the extent and nature of the security weaknesses contributing to the incidents. Requesting an IT security assessment will provide the necessary data to identify specific vulnerabilities and gaps, enabling informed decision-making for remediation.
An IT maturity assessment evaluates the sophistication of processes, but first identifying critical security gaps and vulnerabilities provides more immediate actionable insights into the *current* incident problem.
Mandating a policy update without a clear understanding of the existing gaps and how they relate to policy deficiencies may result in ineffective changes and doesn't directly address the immediate incident problem.
Concept tested: IT Governance Incident Response Prioritization
Source: https://www.iso.org/standard/27001.html
Topics
Community Discussion
No community discussion yet for this question.