- 8
- 0
- 约 10页
- 2017-06-09 发布于北京
- 举报
第六章:灾难恢复与业务连续性计划
C6-1 During an audit, an IS auditor notes that an organizations business continuity plan (BCP) does not adequately address information confidentiality during a recovery process. The IS auditor should recommend that the plan be modified to include:
A .the level of information security required when business recovery procedures are invoked.
B. information security roles and responsibilities in the crisis management structure.
C. information security resource requirements.
D. change management procedures for information security that could affect business continuity arrangeme
原创力文档

文档评论(0)