IT プロジェクトは予算を超えており、ポスト プロダクションに追加されるセキュリティ コントロールが多すぎます。関連する管理がプロジェクトに確実に適用されるようにするために、最も役立つのは次のうちどれですか?
正解:A
Explanation
The best way to ensure that relevant controls are applied to a project is to involve information security at each stage of project management. This will help to identify and address the security risks and requirements of the project from the beginning, and to integrate security controls into the project design, development, testing, and implementation. This will also help to avoid adding unnecessary or ineffective controls post-production, which can increase the project cost and complexity, and reduce the project performance and quality. By involving information security at each stage of project management, the information security manager can ensure that the project delivers the expected security value and aligns with the organization's security strategy and objectives. References = CISM Review Manual 15th Edition, page 41.