QuestionQ435

Security Concepts and Practices

Which of the following would not violate the Due Diligence concept?

  • A Security policy being outdated
  • B Data owners not laying out the foundation of data protection
  • C Network administrator not taking mandatory two-week vacation as planned
  • D Latest security patches for servers being installed as per the Patch Management process
Explanation

Due diligence includes maintaining operational security controls, such as applying current server security patches through the organization’s Patch Management process. This demonstrates reasonable, ongoing effort to reduce known vulnerabilities.

Community Discussion

No comments yet. Be the first to start the discussion!