I'm feeling pretty confident about this one. Option B seems like the best choice - creating multiple domain service inventories is a smart way to address the ownership and governance issues.
This is an interesting question. I think I would start by looking at the organization's incident response policy and procedures to get a baseline understanding of the program. Then I would want to supplement that with staff interviews to see how the policy is actually being implemented. The NIST Cybersecurity Framework could also provide a useful reference point for evaluating the program.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Alton
5 months agoLorean
6 months agoAngella
6 months agoKris
6 months agoGeraldo
6 months agoArlene
6 months agoCammy
6 months agoCaitlin
6 months agoGwen
7 months ago