Last Updated on December 21, 2021 by Admin
Which of the following should be of GREATEST concern to an information security manager when establishing a set of key risk indicators (KRIs)?
- The impact of security risk on organizational objectives is not well understood.
- Risk tolerance levels have not yet been established.
- Several business functions have been outsourced to third-party vendors.
- The organization has no historical data on previous security events.