A CISM is implementing a security control framework. Which of the following is MOST important when selecting a framework?
-
A
It must be mandated by a government agency
-
B
It should align with the organization's risk profile and industry requirements
-
C
It must be the most recently published framework available
-
D
It should be the most widely adopted framework globally