Good day, to all,
This is an interesting discussion, however, it seems people are
thinking too technically and not from a management perspective.
There are two basic ways to many security, the two approaches are
TOP-DOWN and BOTTOM UP.
The TOP-DOWN approach is always the best approach and the one that
should always be used.
The BOTTOM UP is a great recipe for total failure. I tell my
supervisor who tells his supervisor who hopefully brings it up the
management chain and hopefully something gets done. NOT A NICE WAY of
doing business.
Remember, the first step in having great security is to have
MANAGEMENT onboard and it has to be driven from the top down.
Myself, just looking at the questions quickly without looking at any
reference or sources, I would lean toward choice A.
Some of you may be thinking that you never walk into the presidential
office and tell him or her that something is wrong.
You are correct, a well-established security plan would include
policies and some type of incident report. Through the report or the
incident response plan, the issue would be communicated to upper
management.
Just my two cents
Best regards
Clement
> To view this discussion on the web visit
https://groups.google.com/d/msgid/cissptalks/CAP10WQdqV-icOK9cJ4uSpy%2BL8yz0xig43H3NfvM3cR1fSTqnrg%40mail.gmail.com.
---------------------------------------------------------------------------------------------
Clement Dupuis, CD
CCCure Owner and Founder
Chief Learning Officer (CLO) and Security Evangelist
The CCCure Family of Portals
GCFW, GCIA, Security+ 301, CEH V7, CCSA, CCSE, + 12 others
For support or queries send an email to: Sup...@CCCure.Com
----------------------------------------------------------------------------------------------
Maintainer of :
The CCCure Learning Portal - Find the best Security Tutorials
The CCCure Quiz Engine
Knowledge sharing and giving back to the community