組織のセキュリティ要件を満たさない新しいサードパーティのクラウド アプリケーションに関連するリスクに対処するために、情報セキュリティ管理者が最初に行うべきことは次のうちどれですか?
正解:B
Explanation
The information security manager should first consult with the business owner to understand the business needs and objectives for using the new cloud application, and to discuss the possible alternatives or compensating controls that can mitigate the risk. Updating the risk register, restricting application network access, or including security requirements in the contract are possible actions to take after consulting with the business owner.
References = CISM Review Manual, 16th Edition eBook1, Chapter 1: Information Security Governance, Section: Risk Management, Subsection: Risk Treatment, Page 49.