A successful information security management program should use which of the following to determine the amount of resources devoted to mitigating exposures?

  • Post author:
  • Post category:Uncategorized
  • Post comments:0 Comments
  • Post last modified:December 21, 2021
  • Reading time:1 mins read
 

Last Updated on December 21, 2021 by InfraExam

A successful information security management program should use which of the following to determine the amount of resources devoted to mitigating exposures?

  • Risk analysis results
  • Audit report findings
  • Penetration test results
  • Amount of IT budget available
Explanation:
Risk analysis results are the most useful and complete source of information for determining the amount of resources to devote to mitigating exposures. Audit report findings may not address all risks and do not address annual loss frequency. Penetration test results provide only a limited view of exposures, while the IT budget is not tied to the exposures faced by the organization.
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments