CISM Certified Information Security Manager – Question0179

Which of the following is the BEST approach to identify noncompliance issues with legal, regulatory, and contractual requirements?

A.
Risk assessment
B. Business impact analysis (BIA)
C. Vulnerability assessment
D. Gap analysis

Correct Answer: D