List of questions
Related questions
Question 735 - CISA discussion
An IS auditor finds ad hoc vulnerability scanning is in place with no clear alignment to the organization's wider security threat and vulnerability management program.
Which of the following would BEST enable the organization to work toward improvement in this area?
A.
Implementing security logging to enhance threat and vulnerability management
B.
Maintaining a catalog of vulnerabilities that may impact mission-critical systems
C.
Using a capability maturity model to identify a path to an optimized program
D.
Outsourcing the threat and vulnerability management function to a third party
Your answer:
0 comments
Sorted by
Leave a comment first