List of questions
Related questions
Question 281 - CISM discussion
Which of the following should be an information security manager's FIRST course of action when a newly introduced privacy regulation affects the business?
A.
Consult with IT staff and assess the risk based on their recommendations
B.
Update the security policy based on the regulatory requirements
C.
Propose relevant controls to ensure the business complies with the regulation
D.
Identify and assess the risk in the context of business objectives
Your answer:
0 comments
Sorted by
Leave a comment first