QuestionQ999

Information Security Governance

A multinational organization is implementing a security governance framework. The information security manager is concerned that security practices vary by region.

Which of the following should be assessed FIRST?

  • A Training requirements of the framework
  • B Global framework standards
  • C Cross-border data mobility
  • D Local regulatory requirements
Explanation

Local regulatory requirements must be assessed first because they create mandatory jurisdiction-specific obligations that the security governance framework must satisfy. These requirements can constrain global standards, cross-border data mobility, and training requirements.

Community Discussion

No comments yet. Be the first to start the discussion!