Which of the following is the PRIMARY role of the information security manager in application development?
When preventive controls to appropriately mitigate risk are not feasible, the most important action for the information security manager is to manage the impact, which means taking measures to reduce the likelihood or severity of the consequences of the risk. Managing the impact can involve using alternative controls, such as engineering, administrative, or personal protective controls, that can lower the exposure or harm to the organization. The other options, such as identifying unacceptable risk levels, assessing vulnerabilities, or evaluating potential threats, are part of the risk assessment process, but they are not actions to mitigate risk when preventive controls are not feasible. Reference:
https://bcmmetrics.com/risk-mitigation-evaluating-your-controls/
https://www.osha.gov/safety-management/hazard-prevention
https://www.cdc.gov/niosh/topics/hierarchy/default.html
Malcolm
3 months agoWenona
3 months agoCatarina
3 months agoMartina
4 months agoKristofer
4 months agoAlpha
4 months agoTrevor
4 months agoGenevive
4 months agoMerri
5 months agoGregg
5 months agoNakisha
5 months agoClaudia
5 months agoWinifred
5 months agoDevon
5 months agoAleta
5 months agoYuki
5 months agoElke
5 months agoBrendan
5 months agoHayley
10 months agoClaudia
8 months agoMartina
8 months agoChana
8 months agoTamar
8 months agoDaniel
9 months agoFanny
9 months agoBronwyn
10 months agoCecil
8 months agoLeota
9 months agoUna
9 months agoAlecia
10 months agoDorthy
10 months agoEllen
10 months agoJeff
10 months agoLezlie
10 months agoMarci
10 months agoCora
10 months agoDan
10 months agoMelissa
10 months agoFlo
11 months agoLeah
9 months agoRaylene
9 months agoTemeka
10 months agoFrederica
11 months ago