セキュリティ アナリストは、各システムがホストするコンテンツの機密性に基づいて、組織全体のシステムが保護されていることを確認する必要があります。アナリストはそれぞれのシステムを使用して作業しています
所有者は、ホストされているデータの機密性、可用性、完全性を促進するための最良の方法論を決定するのに役立ちます。セキュリティ アナリストが最初に実行すべきことは次のうちどれですか?
それぞれのシステムを分類して優先順位を付けますか?
正解:D
Determining the asset value of each system is the best action to perform first, as it helps to categorize and prioritize the systems based on the sensitivity of the data they host. The asset value is a measure of how important a system is to the organization, in terms of its financial, operational, or reputational impact. The asset value can help the security analyst to assign a risk level and a protection level to each system, and to allocate resources accordingly. The other actions are not as effective as determining the asset value, as they do not directly address the goal of promoting confidentiality, availability, and integrity of the data. Interviewing the users who access these systems may provide some insight into how the systems are used and what data they contain, but it may not reflect the actual value or sensitivity of the data from an organizational perspective. Scanning the systems to see which vulnerabilities currently exist may help to identify and remediate some security issues, but it does not help to categorize or prioritize the systems based on their data sensitivity. Configuring alerts for vendor-specific zero-day exploits may help to detect and respond to some emerging threats, but it does not help to protect the systems based on their data sensitivity.