QuestionQ203

Information Security Governance

Which option is the BEST way to ensure organizational security policies comply with data-security regulatory requirements?

  • A Obtain annual sign-off from executive management.
  • B Align the policies to the most stringent global regulations.
  • C Send the policies to stakeholders for review.
  • D Outsource compliance activities.
Explanation

Aligning security policies with the most stringent applicable global regulations creates a baseline that satisfies weaker regulatory requirements as well. Management sign-off, stakeholder review, and outsourced compliance work do not by themselves ensure that policy requirements match applicable data-security regulations.

Community Discussion

No comments yet. Be the first to start the discussion!