ExamGecko
Question list
Search
Search

Question 266 - CISM discussion

Report
Export

The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization Which of the following should be done FIRST?

A.
Inform senior management
Answers
A.
Inform senior management
B.
Re-evaluate the risk
Answers
B.
Re-evaluate the risk
C.
Implement compensating controls
Answers
C.
Implement compensating controls
D.
Ask the business owner for the new remediation plan
Answers
D.
Ask the business owner for the new remediation plan
Suggested answer: B

Explanation:

The first step when a new vulnerability is identified is to re-evaluate the risk associated with the vulnerability. This may require an update to the risk assessment and the implementation of additional controls. Informing senior management of the vulnerability is important, but should not be the first step. Implementing compensating controls may also be necessary, but again, should not be the first step. Asking the business owner for a remediation plan may be useful, but only after the risk has been re-evaluated.

The information security manager should first re-evaluate the risk posed by the new vulnerability to determine its impact and likelihood. Based on this assessment, appropriate actions can be taken such as informing senior management, implementing compensating controls, or requesting a remediation plan from the business owner. The other choices are possible actions but not necessarily the first one.

A vulnerability is a weakness that can be exploited by an attacker to compromise a system or network2.A vulnerability can affect key data processing systems within an organization if it exposes sensitive information, disrupts business operations, or damages assets2.A vulnerability assessment is a process of identifying and evaluating vulnerabilities and their potential consequences2

asked 01/10/2024
Mohamed Isaaq
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first