ExamGecko
Question list
Search
Search

Question 449 - CISM discussion

Report
Export

An information security manager has recently been notified of potential security risks associated with a third-party service provider. What should be done NEXT to address this concern?

A.
Escalate to the chief risk officer (CRO).
Answers
A.
Escalate to the chief risk officer (CRO).
B.
Conduct a vulnerability analysis.
Answers
B.
Conduct a vulnerability analysis.
C.
Conduct a risk analysis.
Answers
C.
Conduct a risk analysis.
D.
Determine compensating controls.
Answers
D.
Determine compensating controls.
Suggested answer: C

Explanation:

A risk analysis is the next step to identify and evaluate the potential security risks associated with a third-party service provider and determine the appropriate risk response strategies.Reference= CISM Review Manual, 16th Edition, Domain 2: Information Risk Management, Chapter 2: Risk Identification, p.97-981; Chapter 3: Risk Assessment, p.109-1101; Chapter 4: Risk Response, p.123-1241

asked 01/10/2024
Tom Rez
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first