A hospital IRM lead wants threat-intelligence headlines to inform risk context without converting Risk into Security Incident Response. Which approach fits?
Select an answer to reveal the explanation.
Short Explanation
Threat intel is seasoning, not the whole meal. Drop a short context note on the related technology risk, keep treatment in the risk lifecycle, and leave SIR playbooks for actual security incidents.
Full Explanation
IRM can consume external threat context to sharpen technology-risk discussion without becoming a security operations product. Architecture should enrich risk records lightly while retaining risk assessment and response in IRM. Routing every advisory through SIR playbooks or forcing incidents before score updates crosses into CIS-SIR territory and misplaces the control of residual risk.