A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate action should the information security manager take?
A.
Enforce the existing security standards and do not allow the deployment of the new technology.
B.
If the risks associated with that technology are not already identified, perform a risk analysis to quantify the risk, and allow the business unit to proceed based on the identified risk level.
C.
Amend the standard to permit the deployment.
D.
Permit a 90-day window to see if an issue occurs and then amend the standard if there are no issues.
Agreed. Policy and security standards are not subjective, they are to be followed. If exceptions are to be made, it must go through an approval process rather than allowed to proceed and management catches up to the problem. Allowing a precedent to happen opens the doors to other departments performing the same action causing disorganized management
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ludikraut
1 year, 4 months agoadv87
3 months, 3 weeks ago