ある組織では、認証機関によって大幅に改訂されたセキュリティ標準を使用しています。認証を維持したい組織では、古いバージョンの標準は使用できなくなります。最初に行うべき行動は次のうちどれですか。
正解:B
Reviewing the new standard for applicability to the business is the first course of action, as it helps to understand the changes, gaps, and impacts of the revision on the organization's security posture, compliance status, and business objectives. Evaluating the cost of maintaining the certification, modifying policies to ensure new requirements are covered, and communicating the new standard to senior leadership are important steps, but they should be done after reviewing the new standard for applicability to the business.
References = CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.2