The Chief Information Security Officer (CISO) of a medium-sized business plans to modernize the existing security infrastructure and address issues with legacy software and assets. Which of the following should the CISO use to determine the scope of the legacy infrastructure and develop a risk-based approach to modernization?
Which of the following is a reason why a forensic specialist would create a plan to preserve data after an modem and prioritize the sequence for performing forensic analysis?
Which of the following practices would be best to prevent an insider from introducing malicious code into a company's development process?
Which of the following describes how a risk event might affect operations and limit the overall risk score?
Which of the following methods would most likely be used to identify legacy systems?