Question 475:
A CEO requires that information security risk management is practiced at the organizational level through a central risk register. Which of the following is the MOST important reason to report a summary of this risk register to the board?
Answer options:
A. To facilitate alignment between risk management and organizational objectives B. To ensure adequate funding is available for risk management and mitigation C. To comply with the organization`s regulatory and legal requirements D. To ensure alignment with industry standards and trends