CISM Certified Information Security Manager – Question1220

Which of the following is MOST relevant for an information security manager to communicate to business units?

A.
Threat assessments
B. Vulnerability assessments
C. Risk ownership
D. Business impact analysis (BIA)

Correct Answer: D