QuestionQ392

Information Security Program

An organization faces severe fines and penalties if it does not comply with local regulatory requirements by an established deadline. Senior management has asked the information security manager to prepare an action plan for achieving compliance. Which of the following would provide the MOST useful information for planning purposes?

  • A Results from a business impact analysts (BIA)
  • B Results from a gap analysis
  • C An inventory of security controls currently in place
  • D Deadlines and penalties for noncompliance
Explanation

A gap analysis identifies the differences between the current state of security controls and the required compliance state. It therefore identifies the remediation work needed to meet the regulatory requirements and supports prioritizing actions before the deadline.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!