ExamGecko
Question list
Search
Search

Question 570 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST to address the risk associated with a new third-party cloud application that will not meet organizational security requirements?

A.
Update the risk register.
Answers
A.
Update the risk register.
B.
Consult with the business owner.
Answers
B.
Consult with the business owner.
C.
Restrict application network access temporarily.
Answers
C.
Restrict application network access temporarily.
D.
Include security requirements in the contract.
Answers
D.
Include security requirements in the contract.
Suggested answer: B

Explanation:

The information security manager should first consult with the business owner to understand the business needs and objectives for using the new cloud application, and to discuss the possible alternatives or compensating controls that can mitigate the risk. Updating the risk register, restricting application network access, or including security requirements in the contract are possible actions to take after consulting with the business owner.

Reference= CISM Review Manual, 16th Edition eBook1, Chapter 1: Information Security Governance, Section: Risk Management, Subsection: Risk Treatment, Page 49.

asked 01/10/2024
FOTIS FOURLIAS
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first