While it is crucial that the policy is communicated and that training is provided, this can be addressed relatively quickly once identified. Therefore A is not the correct answer
C is the right answer. If the information security policy has not defined roles and responsibilities, there is a significant risk that critical security tasks may not be performed or may be performed inadequately. This could lead to unclear accountability and a lack of ownership for essential security functions, making the organization vulnerable to security incidents.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
thusharaj
2 months, 3 weeks agothusharaj
2 months, 3 weeks agojoehong
7 months, 1 week ago