Question 1 of 30
The efficiency study reveals that the organization\'s information security framework is not effectively supporting its strategic business objectives, leading to a reactive rather than proactive approach to risk management. Which of the following approaches best addresses this situation to establish a more aligned and effective framework?
Conduct a comprehensive impact assessment of potential information security incidents on business operations and strategic goals, and then integrate the findings into the risk treatment plan to prioritize controls that directly mitigate these impacts.
Immediately implement a broad range of advanced technical security controls across all systems to ensure maximum protection against all conceivable threats.
Focus on achieving certification by meticulously documenting compliance with every clause of ISO 27001, regardless of its direct relevance to the organization's specific risks or strategic priorities.
Prioritize security training for all employees on general cybersecurity best practices without first understanding the specific risks and strategic implications for the organization.