ExamGecko
Question list
Search
Search

Question 317 - CISM discussion

Report
Export

An organization plans to leverage popular social network platforms to promote its products and services. Which of the following is the BEST course of action for the information security manager to support this initiative?

A.
Establish processes to publish content on social networks.
Answers
A.
Establish processes to publish content on social networks.
B.
Assess the security risk associated with the use of social networks.
Answers
B.
Assess the security risk associated with the use of social networks.
C.
Conduct vulnerability assessments on social network platforms.
Answers
C.
Conduct vulnerability assessments on social network platforms.
D.
Develop security controls for the use of social networks.
Answers
D.
Develop security controls for the use of social networks.
Suggested answer: B

Explanation:

The best course of action for the information security manager to support the initiative of leveraging popular social network platforms to promote the organization's products and services is to assess the security risk associated with the use of social networks. Security risk assessment is a process of identifying, analyzing, and evaluating the potential threats and vulnerabilities that may affect the confidentiality, integrity, and availability of information assets and systems. By conducting a security risk assessment, the information security manager can provide valuable input to the decision-making process regarding the benefits and costs of using social networks, as well as the appropriate security controls and mitigation strategies to reduce the risk to an acceptable level. The other options are not the best course of action, although they may be part of the security risk management process. Establishing processes to publish content on social networks is an operational task that should be performed after assessing the security risk and implementing the necessary controls. Conducting vulnerability assessments on social network platforms is a technical activity that may not be feasible or effective, as the organization does not have control over the platforms' infrastructure and configuration. Developing security controls for the use of social networks is a preventive measure that should be based on the results of the security risk assessment and aligned with the organization's risk appetite and tolerance

asked 01/10/2024
Lin Sun
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first