上級管理職は、外部の脅威環境の変化に対応して、組織のサイバーセキュリティ プログラムへの投資を増やしたいと考えています。投資努力の優先順位付けに最も役立つのは次のうちどれですか。
正解:D
The best tool to help prioritize investment efforts in the organization's cybersecurity program is to review the outcome of the latest security risk assessment. A security risk assessment is a process of identifying, analyzing, and evaluating the risks associated with the confidentiality, integrity, and availability of the organization's information assets and systems. By reviewing the outcome of the security risk assessment, senior management can identify the most critical and urgent risks, and allocate the resources and fundsaccordingly. Analyzing cyber intelligence reports, engaging independent cybersecurity consultants, and increasing the frequency of updates to the risk register are other possible tools, but they are not as effective as reviewing the outcome of the security risk assessment. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 12; CRISC Review Manual,
6th Edition, page 215.