Q: 18
The board of an organization has been informed of possible cyberthreats. Which of the following
should be the board’s NEXT course of action?
Options
Discussion
D . The board shouldn't jump right into evaluating controls or reassessing risk tolerance without first having a proper assessment of the actual risk at hand. It's not their job to do the analysis themselves, but to delegate that to the CIO or equivalent so they get an informed picture before making any policy or appetite decisions. If there was already a confirmed incident, A might be closer, but here it's just potential threats. Anyone disagree?
Man, ISACA loves the vision statement questions. A imo, always pops up in these practice sets.
Be respectful. No spam.
Question 18 of 35