Question 1 of 15
The system owner proposes a continuous-monitoring strategy that duplicates several organization-level monitoring activities but omits controls unique to the system. What should the information security manager require before approving the strategy?
Strong Interview Answer
The information security manager should require a thorough gap analysis to identify and address controls unique to the system, ensuring comprehensive coverage and avoiding duplication of effort. This involves a detailed assessment of the system’s specific risks and vulnerabilities, supplementing the organizational strategy with targeted controls.
What to Listen For
- Gap Analysis
- System-Specific Controls
- Risk Assessment
- Coverage
- Duplication of Effort
Caution
Ensure the response focuses on the process of identifying and addressing gaps, not simply stating the need for controls.