CRISC · Question #463
Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?
The correct answer is D. Visibility into all networked devices. To effectively assess IoT risk exposure, an organization must first have comprehensive visibility into all IoT devices connected to its network.
Question
Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?
Options
- ADefined remediation plans
- BManagement sign-off on the scope
- CManual testing of device vulnerabilities
- DVisibility into all networked devices
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C14% (3)
- D76% (16)
Why each option
To effectively assess IoT risk exposure, an organization must first have comprehensive visibility into all IoT devices connected to its network.
Defined remediation plans are crucial for managing risks after they have been identified, but they cannot be created without first understanding the full scope of devices and their vulnerabilities.
Management sign-off on the scope is important for governance but does not, by itself, provide the technical information needed to identify actual risk exposure of IoT devices.
Manual testing of device vulnerabilities is a valuable technique but is only effective for devices that have already been identified and brought into scope, and it may not scale for a large number of IoT devices.
Comprehensive visibility into all networked IoT devices is paramount because unknown or unmonitored devices cannot be protected or assessed for vulnerabilities. Without full visibility, an organization cannot identify its complete attack surface, making it impossible to accurately determine risk exposure or implement effective security measures.
Concept tested: IoT device inventory and visibility
Topics
Community Discussion
No community discussion yet for this question.