A county privacy office asks whether IRM is the same as a security operations center tool for handling breaches. What distinction should be taught?
Select an answer to reveal the explanation.
Short Explanation
IRM is the control-and-risk ledger, not the firehouse radio. Breach playbooks and vuln queues live in other products; IRM asks whether policies, risks, and evidence still hold for the county’s entities.
Full Explanation
CIS-RC covers Integrated Risk Management / GRC Risk and Compliance: entities, policy and compliance, risk, audit, and common elements. Security Incident Response (CIS-SIR) and Vulnerability Response (CIS-VR) address operational security incident and vulnerability lifecycles. Confusing IRM with SOC tooling or SIEM is out of scope for the correct positioning.