An IS auditor is reviewing an organization's IT risk management process. Which of the following is the MOST critical first step in this process?
-
A
Developing risk response plans.
-
B
Identifying and classifying information assets.
-
C
Implementing security controls.
-
D
Conducting a business impact analysis (BIA).