ASIS ASIS-CPP Question Answer
After a risk analysis is completed, it is determined that information assets are not adequately protected. In an effort to gain management buy-in for a formal information assets protection program, which of the following is a recommended strategy?