QuestionQ968

Information Security Risk Management

The MAIN purpose of a business-impact-informed guideline for use within a large, international organization is to:

  • A explain the organization's preferred practices for security.
  • B ensure that all business units have the same strategic security goals.
  • C ensure that all business units implement identical security procedures.
  • D provide evidence for auditors that security practices are adequate.
Explanation

Business-impact-informed security guidance establishes consistent organization-wide strategic security goals while permitting business units to apply procedures appropriate to their operational and regulatory contexts.

Community Discussion

No comments yet. Be the first to start the discussion!