Which of the following is the MOST important factor in an organization's selection of a key risk indicator (KRI)?
When preventive controls to appropriately mitigate risk are not feasible, the most important action for the information security manager is to manage the impact, which means taking measures to reduce the likelihood or severity of the consequences of the risk. Managing the impact can involve using alternative controls, such as engineering, administrative, or personal protective controls, that can lower the exposure or harm to the organization. The other options, such as identifying unacceptable risk levels, assessing vulnerabilities, or evaluating potential threats, are part of the risk assessment process, but they are not actions to mitigate risk when preventive controls are not feasible. Reference:
https://bcmmetrics.com/risk-mitigation-evaluating-your-controls/
https://www.osha.gov/safety-management/hazard-prevention
https://www.cdc.gov/niosh/topics/hierarchy/default.html
Lillian
6 months agoKrissy
6 months agoGlennis
7 months agoPeggie
7 months agoCorazon
7 months agoHarrison
7 months agoArlette
7 months agoAfton
8 months agoSarah
8 months agoOmega
8 months agoVilma
8 months agoWhitley
8 months agoDenise
8 months agoEarleen
8 months agoMarkus
8 months agoJina
8 months agoLanie
8 months agoTerrilyn
8 months agoArdella
1 year agoLeonie
1 year agoElmer
11 months agoSherrell
11 months agoCarey
11 months agoPaola
11 months agoRuth
11 months agoJulio
11 months agoJeniffer
12 months agoLynelle
1 year agoJody
1 year agoGracie
12 months agoShawnta
1 year agoElke
1 year agoHubert
1 year agoCiara
11 months agoKristeen
11 months agoColetta
12 months agoGladys
1 year agoBrande
1 year agoDella
1 year agoBrande
1 year ago