LEAD-AUDITOR · Question #263
LEAD-AUDITOR Question #263: Real Exam Question with Answer & Explanation
The correct answer is A. OCTAVE. OCTAVE is a self-directed risk assessment methodology where organizations identify, evaluate, and manage information security risks based on their strategic objectives, aligning with Brian's approach. B. MEHARI is a quantitative risk analysis method, not self-directed. C. EBIOS i
Question
Options
- AOCTAVE
- BMEHARI
- CEBIOS
Explanation
OCTAVE is a self-directed risk assessment methodology where organizations identify, evaluate, and manage information security risks based on their strategic objectives, aligning with Brian's approach. B. MEHARI is a quantitative risk analysis method, not self-directed. C. EBIOS is focused on regulatory compliance and external risk factors, which Brian's methodology did not Thus, Brian's approach aligns best with OCTAVE, as it is self-directed and focuses on organizational security practices.
Community Discussion
No community discussion yet for this question.