List of questions
Related questions
Question 449 - CISM discussion
An information security manager has recently been notified of potential security risks associated with a third-party service provider. What should be done NEXT to address this concern?
A.
Escalate to the chief risk officer (CRO).
B.
Conduct a vulnerability analysis.
C.
Conduct a risk analysis.
D.
Determine compensating controls.
Your answer:
0 comments
Sorted by
Leave a comment first