An organization uses a security standard that has undergone a major revision by the certifying authority. The old version of the standard will no longer be used for organizations wishing to maintain their certifications. Which of the following should be the FIRST
course of action?
Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?
Which of the following is the PRIMARY reason for an information security manager to periodically review existing controls?
Which of the following should have the MOST influence on an organization's response to a new industry regulation?