Examlex
A Chief Information Security Officer (CISO) is reviewing the results of a gap analysis with an outside cybersecurity consultant. The gap analysis reviewed all procedural and technical controls and found the following: High-impact controls implemented: 6 out of 10 Medium-impact controls implemented: 409 out of 472 Low-impact controls implemented: 97 out of 1000 The report includes a cost-benefit analysis for each control gap. The analysis yielded the following information: Average high-impact control implementation cost: $15,000; Probable ALE for each high-impact control gap: $95,000 Average medium-impact control implementation cost: $6,250; Probable ALE for each medium-impact control gap: $11,000 Due to the technical construction and configuration of the corporate enterprise, slightly more than 50% of the medium-impact controls will take two years to fully implement. Which of the following conclusions could the CISO draw from the analysis?
Critical Thinking
is the process of actively analyzing, assessing, and synthesizing information to form a reasoned judgement.
Skeptical Peer Review
The process of critically evaluating the validity and quality of a research work by experts in the same field who are not part of the research team.
Wishful Thinking
The formation of beliefs or making decisions based on what is pleasing to imagine rather than on evidence, rationality, or reality.
Action System
A structured set of activities designed to achieve specific goals or outcomes.
Q22: A cloud administrator is reviewing the requirements
Q30: With which of the following types is
Q36: The Chief Financial Officer (CFO) of an
Q101: During a security assessment, activities were divided
Q164: Joe, a user, is unable to log
Q165: Joe, an employee, took a company-issued Windows
Q229: A company has entered into a business
Q234: A security engineer is attempting to convey
Q289: A technician has set up a new
Q436: Which of the following is an external