問題文
The information security policy carries an approval date from four years ago and shows no review record since then. Why is the missing review cycle a governance finding rather than a clerical issue?
選択肢
- An unreviewed policy stops reflecting separate numbering scheme, and the enterprise loses archived signed copies that the original approval was meant to create in the organization.
- An unreviewed policy stops reflecting separate numbering scheme, and the enterprise loses visible management mandate notes that the original approval was meant to create in the organization.
- An unreviewed policy stops reflecting changed threat obligations statements, and the enterprise loses visible management mandate notes that the original approval was meant to create in the organization.
- An unreviewed policy stops reflecting changed threat obligations statements, and the enterprise loses archived signed copies that the original approval was meant to create in the organization.