CISM Certified Information Security Manager – Question0159

Which of the following is the MOST effective way of ensuring that business units comply with an information security governance framework?

A.
Integrating security requirements with processes
B. Performing security assessments and gap analysis
C. Conducting a business impact analysis (BIA)
D. Conducting information security awareness training

Correct Answer: B