List of questions
Related questions
Question 19 - CISA discussion
When reviewing an organization's information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:
A.
a risk management process.
B.
an information security framework.
C.
past information security incidents.
D.
industry best practices.
Your answer:
0 comments
Sorted by
Leave a comment first