Which of the following BEST facilitates an information security manager's efforts to obtain senior management commitment for an information security program?
When preventive controls to appropriately mitigate risk are not feasible, the most important action for the information security manager is to manage the impact, which means taking measures to reduce the likelihood or severity of the consequences of the risk. Managing the impact can involve using alternative controls, such as engineering, administrative, or personal protective controls, that can lower the exposure or harm to the organization. The other options, such as identifying unacceptable risk levels, assessing vulnerabilities, or evaluating potential threats, are part of the risk assessment process, but they are not actions to mitigate risk when preventive controls are not feasible. Reference:
https://bcmmetrics.com/risk-mitigation-evaluating-your-controls/
https://www.osha.gov/safety-management/hazard-prevention
https://www.cdc.gov/niosh/topics/hierarchy/default.html
Jacinta
3 months agoJannette
3 months agoAdell
4 months agoBev
4 months agoPearlene
4 months agoElise
4 months agoAnabel
4 months agoJaime
5 months agoIesha
5 months agoTu
5 months agoSheridan
5 months agoIsadora
5 months agoShaun
9 months agoCarin
9 months agoMalissa
8 months agoGeorgene
8 months agoKimberely
8 months agoEzekiel
8 months agoAlita
10 months agoCarmelina
10 months agoCharlene
8 months agoDomingo
8 months agoMaurine
9 months agoJacqueline
10 months agoPolly
9 months agoGwenn
10 months agoGene
11 months agoParis
11 months agoEarleen
11 months agoDiane
11 months ago