QuestionQ798

Information Security Governance

A new law mandates that an organization implement specified security controls. Which of the following should the information security manager do FIRST?

  • A Integrate the new requirements into the security policy.
  • B Perform a gap analysis on the new requirements.
  • C Develop a control implementation plan.
  • D Assess the risk of noncompliance with the new requirements.
Explanation

A gap analysis compares existing security controls with the newly mandated requirements and identifies the deficiencies that must be addressed. Its results inform policy updates and the control implementation plan.

Community Discussion

No comments yet. Be the first to start the discussion!