For a significant proposed purchase and new procedure for an organization, a risk assessment and business impact analysis (BIA) have been finished. The business department manager and the information security manager debate about who will be in charge of assessing the outcomes and identified risks. Which of the following would be the information security manager's BEST course of action?
-
A
Acceptance of the information security manager’s decision on the risk to the corporation
-
B
Acceptance of the business manager’s decision on the risk to the corporation
-
C
Create a new risk assessment and BIA to resolve the disagreement
-
D
Review of the risk assessment with executive management for final input