Which of the following should be an IS auditor's GREATE ST concern when reviewing an organization's security controls for policy compliance?
A、Security policies are not applicable across all business units
B、The security policy has not been reviewed within the past year
C、Security policy documents are available on a public domain website
D、End users are not required to acknowledge security policy training
发布时间:2025-01-30 08:47:34