An organisation operates in a sector subject to several overlapping laws and regulations, and senior management is frustrated that compliance work is duplicated across departments. The information security manager has been asked to make legal and regulatory obligations a manageable input to the governance framework. What should the manager do first to achieve this?
- AAdopt a single internationally recognised security framework and assume that certification against it will satisfy each applicable law and regulation.
- BDevelop a consolidated register of applicable legal and regulatory obligations mapped to the controls that satisfy them. Correct
- CAssign each department to track its own obligations independently so that the staff closest to each law retain ownership of it.
- DSchedule an external audit of current compliance so an independent party can list the obligations the organisation is breaching.
Why A is wrong: Certifying to one framework is appealing as a shortcut, but a framework does not automatically map to every jurisdiction-specific legal duty, so gaps and duplicated effort would persist undetected.
Why B is correct: A consolidated obligations register mapped to controls reveals where one control satisfies several requirements, removes duplicated effort, and turns scattered legal duties into a structured input the governance framework can manage.
Why C is wrong: Local ownership sounds responsive and is tempting, but leaving each department to track obligations independently is the very source of the duplication and inconsistency management already complained about.
Why D is wrong: An external audit can be valuable later, but commissioning one before the obligations are even catalogued is premature and costly, and it outsources understanding that the organisation needs to own internally.