QuestionQ242

Information Security Risk Management

Which of the following should serve as the PRIMARY basis for determining information security objectives?

  • A Business strategy
  • B Regulatory requirements
  • C Information security strategy
  • D Data classification
Explanation

Information security objectives must align with and support the organization’s business strategy, ensuring that security investments and priorities enable business goals. Regulatory requirements, the information security strategy, and data classification are important inputs, but they are subordinate to the business context.

Community Discussion

No comments yet. Be the first to start the discussion!