A board of a large organization is considering certification of the organization’s information security management system to an internal standard. The board expects the certification to help retain and attract customers and reach new markets. CISO and information security managers estimated the costs of certification and necessary preparations and think that some requirements of the standard are too expensive to meet compared to the risks they address.
What is the BEST course of action for the organization in this situation?