ExamGecko
Question list
Search
Search

Question 343 - CISM discussion

Report
Export

Regular vulnerability scanning on an organization's internal network has identified that many user workstations have unpatched versions of software. What is the BEST way for the information security manager to help senior management understand the related risk?

A.
Include the impact of the risk as part of regular metrics.
Answers
A.
Include the impact of the risk as part of regular metrics.
B.
Recommend the security steering committee conduct a review.
Answers
B.
Recommend the security steering committee conduct a review.
C.
Update the risk assessment at regular intervals
Answers
C.
Update the risk assessment at regular intervals
D.
Send regular notifications directly to senior managers
Answers
D.
Send regular notifications directly to senior managers
Suggested answer: A

Explanation:

Including the impact of the risk as part of regular metrics is the best way for the information security manager to help senior management understand the related risk of having many user workstations with unpatched versions of software because it quantifies and communicates the potential consequences and likelihood of such a risk in terms of business objectives and performance indicators. Recommending the security steering committee conduct a review is not a good way because it does not provide any specific information or analysis about the risk or its impact. Updating the risk assessment at regular intervals is not a good way because it does not ensure that senior management is aware or informed about the risk or its impact. Sending regular notifications directly to senior managers is not a good way because it may be perceived as intrusive or annoying, and may not convey the severity or urgency of the risk or its impact.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2015/volume-6/measuring-the-value-of-information-security-investments https://www.isaca.org/resources/isaca-journal/issues/2017/volume-3/how-to-measure-the-effectiveness-of-your-information-security-management-system

asked 01/10/2024
Joseph McCray
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first