Which of the following is a correct statement about the balance among prevention, detection, and response (PDR)? a. Organizations have no discretion in deciding their levels of security practice. b. If detection and response measures are in place, it is not necessary to have measures devoted to prevention. c. If preventive measures are in place, it is not necessary to have measures focused on detection and response. d. The greater the sensitivity and quantity of the data at issue, the more carefully the balance among these three must be evaluated.

Respuesta :

Option D , The greater the sensitivity and quantity of the data at issue, the more carefully the balance among these three must be evaluated.

Explanation:

Prevention, detection and response are one of the fundamental triads of cyber security.

Maybe it was important to invest most of the Info-Sec spending on mitigation in the late nineties and the first half of the 2000s. However, the alterations they have seen in technology, threats and the economy over the last five to seven years have inevitably led to successful assaults by organisations. Consequently, the detection and response should be allocated more budget.