List of questions
Related questions
Question 144 - CISM discussion
Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?
A.
Security policy
B.
Risk management framework
C.
Risk appetite
D.
Security standards
Your answer:
0 comments
Sorted by
Leave a comment first