CompTIA CySA+CS0-002 – Question127

A company has started planning the implementation of a vulnerability management procedure. However, its security maturity level is low. So there are some prerequisites to complete before risk calculation and prioritization.
Which of the following should be completed FIRST?

A.
A business impact analysis
B. A system assessment
C. Communication of the risk factors
D. A risk identification process

Correct Answer: D