QuestionQ36

Protection of Information Assets

Which issue identified during a formal review of an organization’s information security policies poses the GREATEST potential risk to the organization?

Explanation

Information security policies must align with the organization’s information security risk appetite so that required controls and risk-treatment decisions reflect the level and types of risk the organization is willing to accept. Misalignment can leave material risks insufficiently addressed or impose controls inconsistent with approved risk tolerance.

Community Discussion

No comments yet. Be the first to start the discussion!