154k views
3 votes
A Chief Information Security Officer (CISO) is reviewing the controls in place to support the organization's vulnerability management program. The CISO finds patching and vulnerability scanning policies and procedures are in place. However, the CISO is concerned the organization is siloed and is not maintaining awareness of new risks to the organization. The CISO determines systems administrators need to participate in industry security events.

Which of the following is the CISO looking to improve?

A. Vendor diversification
B. System hardening standards
C. Bounty programs
D. Threat awareness
E. Vulnerability signatures

1 Answer

6 votes

Final answer:

The CISO is looking to improve threat awareness by having systems administrators participate in industry security events.

Step-by-step explanation:

The CISO is looking to improve threat awareness. The concern is that the organization is not maintaining awareness of new risks to the organization due to being siloed.

By having systems administrators participate in industry security events, the organization can stay updated on emerging threats and better protect against them.

User Darkonaut
by
7.5k points