Question 381
The cost of implementing a security control should not exceed the:
Question 382
An information security team has been tasked with identifying confidential data within the organization to formalize its asset classification scheme. The MOST relevant input would be provided by:
Question 383
When performing a quantitative risk analysis, which of the following is MOST important to estimate the potential loss?
Question 384
In an organization implementing a data classification program, ultimate responsibility for the data on the database server lies with the:
Question 385
Which of the following is MOST important to consider when prioritizing threats during the risk assessment process?