Which of the following statements about the maintenance and review of information security policies is NOT true?

Which of the following statements about the maintenance and review of information security policies is NOT true?

Which of the following statements about the maintenance and review of information security policies is NOT true?

A.
The review and maintenance of security policies should be tied to the performance evaluations of accountable individuals.

B.
Review requirements should be included in the security policies themselves.

C.
When business requirements change, security policies should be reviewed to confirm that policies reflect the new business requirements.

D.
Functional users and information custodians are ultimately responsible for the accuracy and relevance of information security policies.

E.
In the absence of changes to business requirements and processes, information-security policy reviews should be annual.



Leave a Reply 1

Your email address will not be published. Required fields are marked *