組織のセキュリティ要件を満たさない新しいサードパーティのクラウド アプリケーションに関連するリスクに対処するために、情報セキュリティ マネージャーが最初に行うべきことはどれですか。
正解:B
The information security manager should first consult with the business owner to understand the business needs and objectives for using the new cloud application, and to discuss the possible alternatives or compensating controls that can mitigate the risk. Updating the risk register, restricting application network access, or including security requirements in the contract are possible actions to take after consulting with the business owner.
References = CISM Review Manual, 16th Edition eBook1, Chapter 1: Information Security Governance, Section: Risk Management, Subsection: Risk Treatment, Page 49.