List of questions
Related questions
Question 698 - CRISC discussion
An organization discovers significant vulnerabilities in a recently purchased commercial off-the-shelf software product which will not be corrected until the next release. Which of the following is the risk manager's BEST course of action?
A.
Review the risk of implementing versus postponing with stakeholders.
B.
Run vulnerability testing tools to independently verify the vulnerabilities.
C.
Review software license to determine the vendor's responsibility regarding vulnerabilities.
D.
Require the vendor to correct significant vulnerabilities prior to installation.
Your answer:
0 comments
Sorted by
Leave a comment first