ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 1475 - CISSP discussion

Report
Export

Information Security Continuous Monitoring (1SCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. Which of the following is the FIRST step in developing an ISCM strategy and implementing an ISCM program?

A.
Define a strategy based on risk tolerance that maintains clear visibility into assets, awareness of vulnerabilities, up-to-date threat information, and mission/business impacts.
Answers
A.
Define a strategy based on risk tolerance that maintains clear visibility into assets, awareness of vulnerabilities, up-to-date threat information, and mission/business impacts.
B.
Conduct a vulnerability assessment to discover current threats against the environment and incorporate them into the program.
Answers
B.
Conduct a vulnerability assessment to discover current threats against the environment and incorporate them into the program.
C.
Respond to findings with technical management, and operational mitigating activities or acceptance, transference/sharing, or avoidance/rejection.
Answers
C.
Respond to findings with technical management, and operational mitigating activities or acceptance, transference/sharing, or avoidance/rejection.
D.
Analyze the data collected and report findings, determining the appropriate response. It may be necessary to collect additional information to clarify or supplement existing monitoring data.
Answers
D.
Analyze the data collected and report findings, determining the appropriate response. It may be necessary to collect additional information to clarify or supplement existing monitoring data.
Suggested answer: A
asked 18/09/2024
Franco Santos
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first