Q: 14
Which of the following MUST be defined in order for an information security manager to evaluate
the appropriateness of controls currently in place?
Options
Discussion
Yeah I agree, C is the key here. You can't really say if your controls are too weak or too strong unless you've got the risk appetite defined first. Policies and frameworks help, but the appetite sets that bar. Pretty confident but let me know if you see it differently.
Its C. You need to know the organization's risk appetite to judge if existing controls are enough or overkill. Without that baseline, there's no way to say what level of risk is acceptable. Pretty sure about this, but open to other takes.
Be respectful. No spam.
Question 14 of 35