The correct answer is C because before assessing impact, performing a gap analysis, or conducting a risk assessment, the organization must first determine whether the new regulatory requirement applies to its cloud services, data, jurisdictions, customers, industry, and processing activities. Applicability establishes whether the regulation is relevant and which systems, processes, contracts, business units, or data types are in scope. A risk assessment is important after applicability is confirmed, but performing it too early may waste resources or miss the correct scope. Reviewing the asset inventory may support scoping, but it should follow or support the applicability analysis. A gap analysis compares current practices against requirements, but this cannot be done properly until the organization confirms that the requirement applies and understands its scope. CISM risk management emphasizes identifying legal, regulatory, and contractual obligations as part of risk and compliance management. Therefore, determining applicability is the first step in understanding the impact of a new regulatory requirement.
[Reference: CISM Information Risk Management; regulatory compliance, cloud risk, applicability analysis, and risk assessment scoping principles., , ]
Submit