Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?
Control matrix
Business impact analysis (BIA)
Risk register
Information security policy
Submit