List of questions
Related questions
Question 727 - CRISC discussion
While conducting an organization-wide risk assessment, it is noted that many of the information security policies have not changed in the past three years. The BEST course of action is to:
A.
review and update the policies to align with industry standards.
B.
determine that the policies should be updated annually.
C.
report that the policies are adequate and do not need to be updated frequently.
D.
review the policies against current needs to determine adequacy.
Your answer:
0 comments
Sorted by
Leave a comment first