An organization is undergoing a complex divestiture of a business unit. What is the security manager's PRIMARY responsibility to ensure alignment with business strategy? Conducting a comprehensive risk assessment of the remaining infrastructure Your Answer Defining and negotiating the security requirements in the transition service agreement Correct Revoking all logical access for employees transitioning to the new entity Updating the security policy to reflect the organization's reduced risk profile Explanation: Correct Answer B. Defining and negotiating the security requirements in the transition service agreement Explanation (CISSP Manager Logic) During a divestiture, the Transition Service Agreement (TSA) is the critical document that governs how services (and data) are shared until the split is complete. The security manager must ensure that security obligations, liability, and data protection standards are explicitly defined to protect the parent organization's interests while enabling business continuity. By defining and negotiating these requirements, you Ensure legal and regulatory compliance during the high-risk transition phase. Protect the parent organization from liabilities arising from the divested unit's actions. Align security efforts directly with the strategic goals of the business transaction. A: Risk assessments are necessary, but they are a component of the broader strategy defined in the TSA. C: Revoking access is a tactical task that must follow the timeline and legal constraints established in the TSA. D: Policy updates are a late-stage administrative task that does not address the immediate strategic risks of the divestiture process. Think like a manager Strategic security management in M&A or divestitures requires focusing on the contractual and legal frameworks that define shared risk and operational boundaries.