Achieving security objectives
What are people currently doing to achieve security objectives? Where do those security objectives originate? Who are the people who are engaged in security and what are their reasons for engagement?
Sample Answer
There are a number of things that people are currently doing to achieve security objectives. These include:
- Implementing security controls: Security controls are measures that are put in place to protect systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction. Some common security controls include firewalls, intrusion detection systems, and access control lists.
- Educating employees about security: Employees are often the weakest link in the security chain. By educating employees about security risks and best practices, organizations can help to protect their systems and data.
- Monitoring for threats and vulnerabilities: Organizations need to continuously monitor their systems and data for threats and vulnerabilities. This can be done through a variety of methods, such as vulnerability scanning and penetration testing.
- Responding to incidents: When a security incident occurs, organizations need to be able to respond quickly and effectively. This includes containing the incident, restoring systems and data, and investigating the incident to prevent it from happening again.