ExamGecko
Question list
Search
Search

Related questions











Question 735 - CISA discussion

Report
Export

An IS auditor finds ad hoc vulnerability scanning is in place with no clear alignment to the organization's wider security threat and vulnerability management program.

Which of the following would BEST enable the organization to work toward improvement in this area?

A.
Implementing security logging to enhance threat and vulnerability management
Answers
A.
Implementing security logging to enhance threat and vulnerability management
B.
Maintaining a catalog of vulnerabilities that may impact mission-critical systems
Answers
B.
Maintaining a catalog of vulnerabilities that may impact mission-critical systems
C.
Using a capability maturity model to identify a path to an optimized program
Answers
C.
Using a capability maturity model to identify a path to an optimized program
D.
Outsourcing the threat and vulnerability management function to a third party
Answers
D.
Outsourcing the threat and vulnerability management function to a third party
Suggested answer: C

Explanation:

The best way to enable the organization to work toward improvement in its security threat and vulnerability management program is to use a capability maturity model to identify a path to an optimized program.A capability maturity model is a framework that helps organizations assess their current level of performance and maturity in a specific domain, and provides guidance and best practices to achieve higher levels of excellence12.A capability maturity model for vulnerability management can help the organization to evaluate its current practices, identify gaps and weaknesses, and implement improvement actions based on the defined criteria and objectives34.

Reference

1: What is a Capability Maturity Model?12: Capability Maturity Model - Wikipedia23: Vulnerability Management Maturity Model - SANS Institute44: 5 Stages Of Vulnerability Management Maturity Model - SecPod Blog3

asked 18/09/2024
Yuri Shpovlov
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first