B. update the risk assessment.
Updating the risk assessment is crucial because it allows the organization to identify and evaluate any new security risks or vulnerabilities introduced by the code change. This ensures that the security posture of the application remains current and effective. While the other options are also important, such as informing senior management, validating UAT, and modifying key risk indicators, they should be considered as complementary actions rather than the most critical one in the context of security. Updating the risk assessment provides a foundation for making informed decisions regarding the other actions.
A significant change to the underlying code of an application can introduce new vulnerabilities, risks, and potential security issues. Therefore, it is crucial for the information security manager to update the risk assessment to reflect the changes and assess the impact on the overall security posture of the application.
(A) This is only done after the risk assessment
(B) It's a risk assessment that needs to occur cause risk is based on impact and probability, both which are based on the attack surface which of course is based on the functionality of the app. This is what has changed and needs to be reflected in the risk assessment
(C) Information security should be focused on UAT that's a developer role
(D) KRI probable but unlikely.
I think there's no better answer than A. INFOSEC manager dont update but perform risk assessment. I am not sure how risk assessment can be updated, it is the risk register that we need to update.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
eparamo
Highly Voted 4 years agoJoniM
Highly Voted 3 years, 4 months agoLearner76
Most Recent 1 month agooluchecpoint
4 months, 1 week agowello
7 months, 1 week agorichck102
7 months, 1 week agodark_3k03r
10 months agobaranikumar_v
1 year agoD2D2
1 year, 1 month agoneji
1 year, 11 months agoAnderV
2 years, 3 months agoRoy34
2 years, 8 months agoHannibal99
2 years, 9 months agoAJ_123
3 years, 5 months agoNdy
3 years, 6 months agomatt6558
3 years, 6 months ago