Business units within an organization are resistant to proposed changes to the information security program. Which of the following is the BEST way to address this issue?
A. Implementing additional security awareness training
B. Communicating critical risk assessment results to business unit
managers
C. Including business unit representation on the security steering
committee
D. Publishing updated information security policies
Correct Answer: B?????? or C??????????
______________________
Note
■ Some experts claim that the correct answer is: "B. Communicating critical risk assessment results to business unit managers"
■ Other experts claim that the correct answer is: "C. Including business unit representation on the security steering committee"
■ What do you think about that? Please explains: Why B and not C......or.......Why C and not B
Many thanks!
The business units within an oraganization are resistant to proposal changes to information security program, the best way to address this issue is Communicating critical risk assessment results to business unit managers, this is said as the information security changes lead to critical assessment to the bysness unit managers, as they have the responsibility of the information security program.
The Including business unit representation on the security steering committee is not suitable as the job role of business unit does not changes to security steering committee so the option suited is the Communicating critical risk assessment results to business unit managers, as here risk assemesnt after changing is a difficult task.
----------------------------------------------Please Upvote--------------------------------------------------------------------------------------
Get Answers For Free
Most questions answered within 1 hours.