IT セキュリティ要件に影響を与える可能性がある新しい規制を組織が認識した場合、IS 監査人が最初に実行することを推奨する必要があるのは、次のうちどれですか?
正解:D
The IS auditor should first review the existing IT controls to identify any gaps between existing controls and the new regulation. This review should then be followed by determining which systems and IT-related processes may be impacted, updating security policies, and evaluating how security awareness and training content may be impacted.