The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization. Which of the following should be done FIRST? A. Re-evaluate the risk. B. Ask the business owner for the new remediation plan. C. Inform senior management. D. Implement compensating controls. Suggested Answer: A This question is in CISM exam For getting Certified Information Security Manager Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISACA. The website does not contain actual questions and answers from ISACA's Certification Exams. Trademarks, certification & product names are used for reference only and belong to ISACA.
Please login or Register to submit your answer