CISM Certified Information Security Manager – Question0765

When considering whether to adopt a new information security framework, an organization’s information security manager should FIRST:

A.
compare the framework with the current business strategy
B. perform a technical feasibility analysis
C. perform a financial viability study
D. analyze the framework’s legal implications and business impact

Correct Answer: A