CS0-003 · Question #109
A company has alerted planning the implemented a vulnerability management procedure. However, to security maturity level is low, so there are some prerequisites to complete before risk calculation…
The correct answer is D. A risk identification process. For a company with low security maturity, the first prerequisite for a vulnerability management procedure, before risk calculation and prioritization, is to identify what the risks are.
Question
A company has alerted planning the implemented a vulnerability management procedure. However, to security maturity level is low, so there are some prerequisites to complete before risk calculation and prioritization. Which of the following should be completed FIRST?
Options
- AA business Impact analysis
- BA system assessment
- CCommunication of the risk factors
- DA risk identification process
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- C12% (3)
- D80% (20)
Why each option
For a company with low security maturity, the first prerequisite for a vulnerability management procedure, before risk calculation and prioritization, is to identify what the risks are.
A business impact analysis (BIA) helps determine the potential effects of an incident, which contributes to risk impact, but it logically follows or runs concurrently with initial risk identification.
A system assessment helps identify vulnerabilities, which are components of risk, but the broader risk identification process encompasses threats, assets, and the overall context before technical assessments.
Communication of risk factors is an outcome of the risk management process, occurring after risks have been identified, analyzed, and prioritized.
Before risk calculation and prioritization can occur, a company must first undertake a risk identification process to discover and document potential threats and vulnerabilities to its assets. Without clearly identified risks, it is impossible to accurately assess their impact or likelihood, or to prioritize them effectively.
Concept tested: Risk management framework - Risk identification
Source: https://csrc.nist.gov/publications/detail/sp/800-39/final
Topics
Community Discussion
No community discussion yet for this question.