Certified Information Security Manager (CISM)Information Security Risk ManagementHard

An organization experiences a significant data breach due to a zero-day vulnerability. Following the incident, the CISO is tasked with improving the organization's ability to anticipate and defend against future advanced threats. Which of the following would be the MOST effective long-term strategy?

  1. ADeveloping and integrating a proactive threat intelligence program.
  2. BPurchasing next-generation firewalls with advanced intrusion prevention capabilities.
  3. CImplementing a robust patch management program for all systems.
  4. DInvesting heavily in security awareness training for all employees.
Show answer & explanation

Correct answer: A. Developing and integrating a proactive threat intelligence program.

A zero-day vulnerability implies an unknown threat. While other options address known vulnerabilities or general defenses, a proactive threat intelligence program specifically focuses on gathering, analyzing, and acting upon information about emerging threats, attacker tactics, and vulnerabilities *before* they are exploited. This enables the organization to anticipate and better defend against future advanced and unknown threats in the long term.

Why the other options are wrong

  • B. Next-gen firewalls are defensive controls, but they are often reactive to known attack patterns and may not inherently anticipate zero-days.
  • C. Patch management addresses known vulnerabilities, but a zero-day is, by definition, unpatched and unknown.
  • D. Awareness training is crucial but primarily addresses human-centric risks, not direct anticipation of zero-day exploits.

Threat Intelligence

Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, implications and actionable advice, about an existing or emerging menace or hazard to assets.

  • Proactive, not reactive.
  • Informs security decisions and defenses.
  • Covers TTPs (Tactics, Techniques, Procedures) of adversaries.

Memory trick: To see the future threats, you need intelligence.

More Information Security Risk Management questions