Isaca Certified Information Security Manager CISM Question # 136 Topic 14 Discussion

Isaca Certified Information Security Manager CISM Question # 136 Topic 14 Discussion

CISM Exam Topic 14 Question 136 Discussion:
Question #: 136
Topic #: 14

A newly appointed information security manager of a retailer with multiple stores discovers an HVAC (heating, ventilation, and air conditioning) vendor has remote access to the stores to enable real-time monitoring and equipment diagnostics. Which of the following should be the information security manager's FIRST course of action?


A.

Conduct a penetration test of the vendor.


B.

Review the vendor's technical security controls


C.

Review the vendor contract


D.

Disconnect the real-time access


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.