ExamGecko
Question list
Search
Search

Question 534 - CISM discussion

Report
Export

An organization has remediated a security flaw in a system. Which of the following should be done NEXT?

A.
Assess the residual risk.
Answers
A.
Assess the residual risk.
B.
Share lessons learned with the organization.
Answers
B.
Share lessons learned with the organization.
C.
Update the system's documentation.
Answers
C.
Update the system's documentation.
D.
Allocate budget for penetration testing.
Answers
D.
Allocate budget for penetration testing.
Suggested answer: A

Explanation:

Residual risk is the risk that remains after applying controls to mitigate the original risk. It is important to assess the residual risk after remediation to ensure that it is within the acceptable level and tolerance of the organization. (From CISM Review Manual 15th Edition)

asked 01/10/2024
EMELINE LE QUENTREC
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first