List of questions
Related questions
Question 780 - CISM discussion
What should be the NEXT course of action when an information security manager has identified a department that is repeatedly not following the security policy?
A.
Perform a vulnerability assessment on the systems within the department.
B.
Introduce additional controls to force compliance with policy.
C.
Require department users to repeat security awareness training.
D.
Report the policy violation to senior management.
Your answer:
0 comments
Sorted by
Leave a comment first