Which of the following is the PRIMARY role of the information security manager in application development?
When preventive controls to appropriately mitigate risk are not feasible, the most important action for the information security manager is to manage the impact, which means taking measures to reduce the likelihood or severity of the consequences of the risk. Managing the impact can involve using alternative controls, such as engineering, administrative, or personal protective controls, that can lower the exposure or harm to the organization. The other options, such as identifying unacceptable risk levels, assessing vulnerabilities, or evaluating potential threats, are part of the risk assessment process, but they are not actions to mitigate risk when preventive controls are not feasible. Reference:
https://bcmmetrics.com/risk-mitigation-evaluating-your-controls/
https://www.osha.gov/safety-management/hazard-prevention
https://www.cdc.gov/niosh/topics/hierarchy/default.html
Hayley
2 months agoClaudia
1 days agoMartina
2 days agoChana
4 days agoTamar
5 days agoDaniel
18 days agoFanny
26 days agoBronwyn
2 months agoCecil
6 days agoLeota
10 days agoUna
15 days agoAlecia
2 months agoDorthy
2 months agoEllen
2 months agoJeff
1 months agoLezlie
1 months agoMarci
1 months agoCora
1 months agoDan
2 months agoMelissa
2 months agoFlo
2 months agoLeah
21 days agoRaylene
29 days agoTemeka
2 months agoFrederica
3 months ago