An information security manager needs to ensure security testing is conducted on a new system. Which of the following would provide the HIGHEST level of assurance?
A.
The vendor provides the results of a penetration test and code review.
B.
An independent party is directly engaged to conduct testing.
C.
The internal audit team is enlisted to run a vulnerability assessment against the system.
D.
The security team conducts a self-assessment against a recognized industry framework.
If I had a talented team, then I would have the highest level of assurance if my team conducted a self-assessment against a recognized industry framework.
B. An independent party is directly engaged to conduct testing.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ATT5832
1 month, 1 week agorichck102
1 year, 5 months ago