I’m not entirely sure, but I think we practiced a question that mentioned the importance of timing in risk assessments. Could that relate to option C too?
Option C is the way to go. Consistent, scheduled risk assessments that are updated as changes occur is crucial for effective information security management.
I'm leaning towards C as well. Performing regular assessments and keeping them current seems like the best way to proactively manage information security risks.
C definitely seems like the most comprehensive and practical approach. Maintaining risk assessments during changes is really important for keeping security up-to-date.
I'm a bit confused on this one. I'm not sure if the external auditor or the yearly assessment is the better approach. I'll have to think it through more.
Jess
3 days agoAnnabelle
8 days agoIlona
13 days agoJean
18 days agoChanel
24 days agoMatilda
29 days agoJennifer
1 month agoKimbery
1 month agoRory
1 month agoMiriam
2 months agoAhmed
2 months agoCamellia
2 months agoTuyet
2 months agoGolda
3 months agoBrendan
3 months agoErinn
3 months agoBrett
3 months agoSheridan
2 months agoLelia
3 months ago