IS 監査人は、主要なインターネット対応システムが攻撃に対して脆弱であり、パッチが利用できないことを発見しました。 監査人はまず何を推奨すべきでしょうか?
正解:D
The first step in addressing a vulnerability is to evaluate the associated risk, which involves assessing the likelihood and impact of a potential exploit. Based on the risk assessment, the appropriate mitigation strategy can be determined, such as implementing a new system, adding firewalls, or decommissioning the server. References: ISACA CISA Review Manual 27th Edition, page 280