Which type of system is MOST effective for prioritizing cyber incidents based on impact and tracking them until they are closed?
An organization recently identified a significant risk related to data exfiltration, and the information security manager is asked to quickly address this issue. The security team suggests a number of different security controls. Which of the following is the BEST approach for selecting controls to manage the risk?
Which of the following should an information security manager do FIRST when there is a conflict between the organization ' s information security policy and a local regulation?
Which of the following should be the PRIMARY basis for an information security strategy?