A newly appointed CISO finds the security program is reactive with no formal strategy. What should be the FIRST priority?
-
A
Deploy a SIEM solution to improve visibility
-
B
Conduct a comprehensive risk assessment to establish a baseline
-
C
Create a security awareness program for all employees
-
D
Hire additional penetration testers