The right answer is D. If the risk of non-compliance is minimal, why doing the bothering task to conduct a gap analysis? It's always: get a clear picture of the situation first and decide for further actions afterwards.
As others have said - first D, then other stuff (if necessary; maybe management decides that it's more cost-effective to pay fines then to implement controls).
Performing a gap analysis involves comparing the organization's current security controls and practices against the specific security controls mandated by the new law. This analysis will identify any gaps or areas where the organization does not meet the requirements.
The first thing the information security manager should do is perform a gap analysis on the new requirements. A gap analysis is a process of comparing the current state of the organization's security against the new legal requirements to identify any areas where the organization falls short of meeting the new requirements. This step is important to identify the specific areas where the organization needs to improve its security controls in order to comply with the new law. Once the gap analysis is complete, the organization can develop a control implementation plan, integrate the new requirements into the security policy, and assess the risk of noncompliance with the new requirements.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Josef4CISM
2 days, 23 hours agoATT5832
1 month, 3 weeks agod7a2ba6
3 weeks, 5 days ago03allen
6 months, 3 weeks agoyottabyte
9 months, 3 weeks agoAlexJacobson
11 months, 3 weeks agoMarcovic00
1 year, 1 month agokoala_lay
1 year, 3 months agokristofer8
1 year, 3 months agorichck102
1 year, 6 months agoBroesweelies
1 year, 11 months ago