The executive management of a domestic organization has announced plans to expand operations to multiple international locations. Which of the following should be the information security manager ' s FIRST step upon learning of these plans?
A.
Perform a gap analysis against international information security standards
B.
Update security training and awareness resources accordingly
C.
Research legal and regulatory requirements impacting the new locations
D.
Prepare localized information security policies for each new location
The first step is to research legal and regulatory requirements for the new locations. Different countries have varying security and privacy laws, and understanding these is critical before adapting policies or procedures.
“Security requirements will vary depending on local legal and regulatory obligations, which must be understood as part of international expansion.”
The ISACA CISM practice database also highlights this step as the initial and critical move in international expansions.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit