Which option represents the highest maturity level of an information security program?
The highest maturity level involves a framework that measures risk and monitors the effectiveness of security controls and the overall program. Policies, awareness training, and compliance are necessary foundations, but continuous measurement supports managed improvement.
Community Discussion