List of questions
Related questions
Question 742 - CISM discussion
An experienced information security manager joins a new organization and begins by conducting an audit of all key IT processes. Which of the following findings about the vulnerability management program should be of GREATEST concern?
A.
Identified vulnerabilities are not published and communicated in awareness programs.
B.
Identified vulnerabilities are not logged and resolved in a timely manner.
C.
The number of vulnerabilities identified exceeds industry benchmarks. D. Vulnerabilities are identified by internal staff rather than by external consultants.
Your answer:
0 comments
Sorted by
Leave a comment first