Which of the following is an information security manager’s BEST course of action to address a significant materialized risk that was not prevented by organizational controls?
Which of the following is an information security manager’s BEST course of action to address a significant materialized risk that was not prevented by organizational controls?
A . Update the business impact analysis (BIA)
B . Update the risk register.
C . Perform root cause analysis.
D . Invoke the incident response plan.
Answer: D
Latest CISM Practice Questions with 1327 Q&As
Updated Study Material | Instant Download | Detailed Answers and Explanations
Subscribe
Login
0 Comments