CV0-003 · Question #602
A Chief Information Security Officer (CISO) is evaluating the company's security management program. The CISO needs to locate all the assets with identified deviations and mitigation measures. Which…
The correct answer is D. A risk register. A risk register is a document that records all of an organization's identified risks, the likelihood and consequences of a risk occurring, the actions that are being taken to reduce those risks, and who is responsible for managing them. This makes it a good tool for the CISO to…
Question
A Chief Information Security Officer (CISO) is evaluating the company's security management program. The CISO needs to locate all the assets with identified deviations and mitigation measures. Which of the following would help the CISO with these requirements?
Options
- AAn SLA document
- BADR plan
- CSOC procedures
- DA risk register
How the community answered
(33 responses)- A6% (2)
- B3% (1)
- D91% (30)
Explanation
A risk register is a document that records all of an organization's identified risks, the likelihood and consequences of a risk occurring, the actions that are being taken to reduce those risks, and who is responsible for managing them. This makes it a good tool for the CISO to identify all the assets with identified deviations and mitigation measures.
Topics
Community Discussion
No community discussion yet for this question.