List of questions
Related questions
Question 74 - CISM discussion
An information security manager learns that IT personnel are not adhering to the information security policy because it creates process inefficiencies. What should the information security manager do FIRST?
A.
Conduct user awareness training within the IT function.
B.
Propose that IT update information security policies and procedures.
C.
Determine the risk related to noncompliance with the policy.
D.
Request that internal audit conduct a review of the policy development process,
Your answer:
0 comments
Sorted by
Leave a comment first