An organization ' s information security policies should be developed PRIMARILY on the basis of:
enterprise architecture (EA).
industry best practices.
a risk management process.
past information security incidents.
Submit