List of questions
Related questions
Question 229 - 712-50 discussion
A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?
A.
A security organization that is adequately staffed to apply required mitigation strategies and regulatory compliance solutions
B.
A clear set of security policies and procedures that are more concept-based than controls-based
C.
A complete inventory of Information Technology assets including infrastructure, networks, applications and data
D.
A clearly identified executive sponsor who will champion the effort to ensure organizational buy-in
Your answer:
0 comments
Sorted by
Leave a comment first