内部監査チームは、ソフトウェア アプリケーションが外部レポート要件の範囲外であると判断しました。次のどれが、アプリケーションがもはや適用可能ではないという経営陣の見解を裏付けるでしょうか。
正解:D
Acknowledgement and attestationinvolveformal confirmationthat an application is no longer in scope for compliance, auditing, or reporting requirements. This typically includes documentation signed by relevant stakeholders confirming that the software no longer processes, stores, or transmits relevant data.
Data inventory and retention (A)is related to managing data assets, not software scope confirmation.
Right to be forgotten (B)pertains toprivacy laws (e.g., GDPR), allowing individuals to request data deletion.
Due care and due diligence (C)focus on security best practices rather than software applicability.
Reference:CompTIA Security+ SY0-701 Official Study Guide, Security Program Management and Oversight domain.