List of questions
Related questions
Question 171 - CISM discussion
An information security manager determines there are a significant number of exceptions to a newly released industry-required security standard. Which of the following should be done NEXT?
A.
Document risk acceptances.
B.
Revise the organization's security policy.
C.
Assess the consequences of noncompliance.
D.
Conduct an information security audit.
Your answer:
0 comments
Sorted by
Leave a comment first