QuestionQ1166

Information Security Governance

What should an information security manager do FIRST when a new cybersecurity regulation is introduced?

  • A Consult corporate legal counsel.
  • B Conduct a cost-benefit analysis.
  • C Update the information security policy.
  • D Perform a gap analysis.
Explanation

Corporate legal counsel should be consulted first to determine whether and how the regulation applies to the organization and to clarify its legal obligations. A gap analysis, policy update, and cost-benefit analysis depend on that interpretation.

Community Discussion

No comments yet. Be the first to start the discussion!