List of questions
Related questions
Question 294 - CISM discussion
A newly appointed information security manager of a retailer with multiple stores discovers an HVAC (heating, ventilation, and air conditioning) vendor has remote access to the stores to enable real-time monitoring and equipment diagnostics. Which of the following should be the information security manager's FIRST course of action?
A.
Conduct a penetration test of the vendor.
B.
Review the vendor's technical security controls
C.
Review the vendor contract
D.
Disconnect the real-time access
Your answer:
0 comments
Sorted by
Leave a comment first