Last Updated on December 21, 2021 by InfraExam
After undertaking a security assessment of a production system, the information security manager is MOST likely to:
- inform the system owner of any residual risks and propose measures to reduce them.
- inform the development team of any residual risks, and together formulate risk reduction measures.
- inform the IT manager of the residual risks and propose measures to reduce them.
- establish an overall security program that minimizes the residual risks of that production system.