QuestionQ434

Information Security Risk Management

A stringent new regulation is being finalized in response to worldwide cybersecurity concerns. What should the information security manager do FIRST?

  • A Monitor industry response to the regulation.
  • B Seek legal counsel on the new regulation.
  • C Validate the applicability of the regulation.
  • D Escalate compliance risk to senior management
Explanation

The initial action is to validate whether the regulation applies to the organization, including its jurisdictions, operations, data, and services. That establishes whether a compliance obligation and related risk exist before seeking legal interpretation or escalating the matter.

Community Discussion

No comments yet. Be the first to start the discussion!