CISM Certified Information Security Manager – Question1031

When recommending a preventive control against cross-site scripting in web applications, an information security manager is MOST likely to suggest:

A.
using https in place of http
B. coding standards and code review
C. consolidating multiple sites into a single portal
D. hardening of the web server’s operating system

Correct Answer: B