QuestionQ621
Information Security ProgramAn information security manager discovers that IT personnel are not complying with the information security policy because it causes process inefficiencies. What should the information security manager do FIRST?
- A Propose that IT update information security policies and procedures.
- B Request that internal audit conduct a review of the policy development process.
- C Conduct user awareness training within the IT function.
- D Determine the risk related to noncompliance with the policy.
Community Discussion