Question 1 of 30
\"Global Dynamics Corp,\" a multinational firm, is developing its Business Continuity Management (BCM) plan. They operate in several countries, including those governed by GDPR. A recent internal audit revealed a lack of integration between the information security management system and the BCM plan. During a simulated disaster recovery scenario, sensitive customer data was potentially exposed due to inadequate access controls on backup systems. The Chief Information Security Officer (CISO), Anya Sharma, is tasked with rectifying this situation. Considering the legal implications and the requirements of ISO 31000:2018, what is the MOST effective course of action for Anya to ensure the integration of information security and BCM, mitigating legal risks and protecting sensitive data?
Integrate information security considerations into the BCM framework, conduct a BCM-specific risk assessment, develop tailored incident response plans for BCM scenarios, and regularly test and review the BCM plan with information security aspects included.
Focus solely on enhancing physical security measures at the disaster recovery site and implementing stricter access controls for personnel involved in the recovery process.
Develop a separate information security plan specifically for disaster recovery scenarios, independent of the existing BCM plan, and conduct annual training sessions for IT staff.
Purchase additional cyber insurance to cover potential data breaches during disaster recovery and implement a data loss prevention (DLP) system on all backup servers.