事業部門の売却に伴い、従業員は新しい組織に異動しますが、以前の雇用主の IT 機器へのアクセス権は保持されます。情報システム監査人は、両組織が機器の許容使用ポリシーに同意し、文書化することを推奨しました。どのようなタイプの管理が推奨されましたか?
正解:B
An acceptable use policy (AUP) is a preventive control that sets out rules and guidelines for using an organization's IT resources, including networks, devices, and software1. It defines acceptable and prohibited behaviors, aiming to protect assets, ensure security, and maintain a productive work environment1. By agreeing to and documenting an AUP for the equipment, both organizations can prevent potential misuse of IT resources2345.
References:
* ISO 27001 Acceptable Use Policy Beginner's Guide - High Table
* Acceptable Use Policy for Information Technology Resources
* Acceptable Use Policies for Workplace Technology | Verizon
* IT Governance: Your Must-Have Policies - How-To Geek
* Acceptable use policy template - Workable