A security engineer receives these findings from a recent security audit:
- Data must be protected according to user permissions and roles.
- User-action tracking must be implemented throughout the network.
- Digital identities must be verified across the data-access workflow.
Which of the following should the engineer do first to address these findings?
Community Discussion