List of questions
Related questions
Question 633 - CISM discussion
A project team member notifies the information security manager of a potential security risk that has not been included in the risk register. Which of the following should the information security manager do FIRST?
A.
Implement compensating controls.
B.
Analyze the identified risk.
C.
Prepare a risk mitigation plan.
D.
Add the risk to the risk register.
Your answer:
0 comments
Sorted by
Leave a comment first