Q: 13
Regular vulnerability scanning on an organization's internal network has identified that many user
workstations have unpatched versions of software. What is the BEST way for the information security
manager to help senior management understand the related risk?
Options
Discussion
Probably A. Metrics actually help management see the impact in their language, not tech speak. Pretty confident on this one.
A since regular metrics translate tech risk into something management actually understands. Just sending updates or doing more frequent assessments won't quite bridge the gap for non-technical execs. Pretty sure ISACA wants us to focus on business impact. Anyone disagree?
C tbh. Updating the risk assessment keeps things current and formalizes the new risk, so management can see changes over time. Figured that's what audit would look for too. Kinda torn since reporting metrics (A) is good, but I always saw reassessment as a go-to first step. Anyone see it different?
Honestly, ISACA loves reporting and metrics for management. Its A
Be respectful. No spam.
Question 13 of 35