A. Executive management has announced an information security risk initiative.
B. IT management has communicated the need for information security risk management to the business.
C. A policy has been communicated stating enterprise commitment and readiness to address information security risk.
D. Procedures have been established for assessing and mitigating information security risks.