Which of the following best explains why an organization might implement a specific security control?
When selecting a cybersecurity control, organizations often prefer solutions that are:
Why is a cost-benefit analysis important before implementing a control?
Which type of events will organizations often address first when implementing controls?
What should a cyber defender consider when determining the most relevant control?
A small medical clinic must comply with strict health data privacy laws. They are considering several security controls:
A: An expensive AI-based threat detection system
B: Encrypted data storage that meets health data compliance standards
C: Security awareness posters in the break room
D: Biometric door locks for all patient rooms
Which control should they prioritize to meet their legal obligations?
A tech startup with a small but highly skilled in-house development team wants to improve security without adding new subscription costs. They prefer a solution that lets them leverage existing employee expertise instead of hiring outside vendors.
Which option best aligns with their goals?
A bank’s risk assessment team identifies several potential threats:
A phishing attack targeting employees (high probability, medium impact)
A rare but devastating natural disaster that could destroy the data center (low probability, high impact)
Occasional slowdowns caused by minor network misconfigurations (medium probability, low impact)
Given limited resources, which risk should they mitigate first?