QuestionQ935

Information Security Governance

What should an information security manager do FIRST when evaluating conflicting requirements between the global organization’s security standards and local regulations?

  • A Conduct a gap analysis against local regulations.
  • B Perform a cost-benefit analysis of compliance.
  • C Create a local version of the organizational standards.
  • D Prioritize the organizational standards over local regulations.
Explanation

A gap analysis against local regulations identifies where the global security standards do not meet, exceed, or conflict with applicable local requirements. This assessment provides the necessary basis for any compliant local implementation or exception.

Community Discussion

No comments yet. Be the first to start the discussion!