Question 326
Which is the BEST solution to monitor, measure, and report changes to critical data in a system?
Question 327
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
Question 328
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs.
What is the MOST logical course of action the CISO should take?
Question 329
With respect to the audit management process, management response serves what function?
Question 330
Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?
