Isaca Certified Information Security Manager CISM Question # 256 Topic 26 Discussion

Isaca Certified Information Security Manager CISM Question # 256 Topic 26 Discussion

CISM Exam Topic 26 Question 256 Discussion:
Question #: 256
Topic #: 26

An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MOST appropriate risk treatment?


A.

Purchase cybersecurity insurance.


B.

Accept the risk associated with continued use of the application.


C.

Implement compensating controls for the application.


D.

Discontinue using the application.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.