I'm feeling pretty confident about this one. Option B seems like the best choice - creating multiple domain service inventories is a smart way to address the ownership and governance issues.
This is an interesting question. I think I would start by looking at the organization's incident response policy and procedures to get a baseline understanding of the program. Then I would want to supplement that with staff interviews to see how the policy is actually being implemented. The NIST Cybersecurity Framework could also provide a useful reference point for evaluating the program.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Alton
4 months agoLorean
4 months agoAngella
4 months agoKris
4 months agoGeraldo
5 months agoArlene
5 months agoCammy
5 months agoCaitlin
5 months agoGwen
5 months ago