Certified Information Systems Security Professional – CISSP – Question190

When evaluating third-party applications, which of the following is the GREATEST responsibility of Information Security?

A.
Accept the risk on behalf of the organization.
B. Report findings to the business to determine security gaps.
C. Quantify the risk to the business for product selection.
D. Approve the application that best meets security requirements.

Correct Answer: C