A security analyst is providing a risk assessment for a medical device that will be installed on the corporate network. During the assessment, the analyst discovers the device has an embedded operating system that will be at the end of its life in two years. Due to the criticality of the device, the security committee makes a risk-based policy decision to review and enforce the vendor upgrade before the end of life is reached.
Which of the following risk actions has the security committee taken?
A. Risk exception
B. Risk avoidance
C. Risk tolerance
D. Risk acceptance
A security analyst is providing a risk assessment for a medical device that will be installed on the corporate network.
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
A security analyst is providing a risk assessment for a medical device that will be installed on the corporate network.
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!