QuestionQ798
Information Security GovernanceA new law mandates that an organization implement specified security controls. Which of the following should the information security manager do FIRST?
- A Integrate the new requirements into the security policy.
- B Perform a gap analysis on the new requirements.
- C Develop a control implementation plan.
- D Assess the risk of noncompliance with the new requirements.
Community Discussion