The correct answer is C because artificial intelligence tools used for vulnerability and control deficiency analysis must integrate effectively with the organization’s existing security infrastructure and technologies. Such tools usually rely on data from vulnerability scanners, configuration management systems, SIEM platforms, endpoint tools, asset inventories, ticketing systems, cloud platforms, and control monitoring solutions. If interoperability is weak, the artificial intelligence capability may receive incomplete, inaccurate, delayed, or inconsistent data, reducing the value of analysis and decision support. Alignment with policies is important, but policy alignment alone will not ensure that the tool can function effectively. Adaptability and scalability are also useful, especially as environments grow, but they are secondary to the tool’s ability to connect with current systems. Training requirements are important for adoption, but training cannot compensate for poor technical integration. From a CISM program management perspective, new security capabilities should be planned to support existing processes, technologies, reporting, and risk management objectives. Therefore, interoperability is the most important consideration.
[Reference: CISM Information Security Program Development and Management; security technology integration, vulnerability management, control monitoring, and program enablement principles., , ]
Submit