Pergunta de entrevista da empresa Updox

What do you do if your upper management doesn't support security objectives?

Resposta da entrevista

Sigiloso

17 de nov. de 2020

I answered that you present the risks by outlining security incident likelihoods and impacts. If qualitative analysis does not sway upper management, quantitative methods can be used to better illustrate the potential for negative financial impact to the business. I also added that in the end, it is upper managements role (CISO, et al) to accept security risk...which they seemed to disagree with.