CISM Certified Information Security Manager – Question0382

Which of the following is the BEST method for determining whether new risks exist in legacy applications?

A.
Regularly scheduled risk assessments
B. Automated vulnerability scans
C. Third-party penetration testing
D. Frequent updates to the risk register

Correct Answer: A