CISA Certified Information Systems Auditor – Question0959

During the due diligence phase of an acquisition, the MOST important course of action for an information security manager would be to:

A.
review the state of security awareness
B. perform a gap analysis
C. perform a risk assessment
D. review information security policies

Correct Answer: C