CompTIA SecurityX (CAS-005) CAS-005 — Question 350
Topic 1 · Question 350 of 393
Topic 1 · Question 350
A Chief Information Security Officer receives the following findings from a third-party risk assessment report: Finding #1: Absence of a risk management process Finding #2: Absence of a formal information security management system Finding #3: Absence of formal procedures to review access Finding #4: Absence of management engagement on monitoring security objectives Which of the following is best for the security team to use when remediating the findings?