CISM · Question #441
Which of the following is the BEST way for an information security manager to ensure security controls effectively address new vulnerabilities?
The correct answer is A. Periodic control review. Conducting periodic control reviews ensures that security controls remain effective in addressing new and emerging vulnerabilities. Regular assessments help identify weaknesses, ensure compliance with security policies, and allow for timely adjustments to security measures. While
Question
Which of the following is the BEST way for an information security manager to ensure security controls effectively address new vulnerabilities?
Options
- APeriodic control review
- BThird-party audit review
- CControl gap analysis
- DVulnerability management plan update
How the community answered
(61 responses)- A74% (45)
- B16% (10)
- C7% (4)
- D3% (2)
Explanation
Conducting periodic control reviews ensures that security controls remain effective in addressing new and emerging vulnerabilities. Regular assessments help identify weaknesses, ensure compliance with security policies, and allow for timely adjustments to security measures. While third-party audits, gap analysis, and vulnerability management updates are useful, they do not provide the ongoing validation of control effectiveness that periodic reviews do.
Topics
Community Discussion
No community discussion yet for this question.