0SG 9th edition - page 109 last paragraph.
Integrating cybersecurity risk management with supply chain, acquisition strategies, and
business practices is a means to ensure a more robust and successful security strategy in
organizations of all sizes. When purchases are made without security considerations, the
risks inherent in those products remain throughout their deployment life span
A strategy that is focused solely on implementing security controls without a clear understanding of the organization's specific risks may result in over-engineering or under-engineering security controls. This can lead to unnecessary expense, operational disruption, or a false sense of security.
Agree with the given Answer: Risk Analysis – Analyzing risk helps you determine your tolerance levels for risk and which you can accept, avoid, transfer, or prevent.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Cyberjerry
6 months, 2 weeks agoHughJassole
1 year, 5 months agoWatcher009
1 year, 6 months agojackdryan
1 year, 6 months agobabaseun
1 year, 7 months agoArsh_2022
1 year, 9 months ago