CISM Certified Information Security Manager – Question1044

The selection of security controls is PRIMARILY linked to:

A.
best practices of similar organizations
B. risk appetite of the organization
C. regulatory requirements
D. business impact assessment

Correct Answer: B