IS 監査人は、パッチ ログから、対象範囲内の一部のシステムが定期的なパッチ適用スケジュールに準拠していないことを発見しました。監査人は次に何をすべきでしょうか?
正解:C
The IS auditor should review the organization's patch management policy to determine the expected frequency and scope of patching, as well as the roles and responsibilities of the patch management team. This will help the auditor assess the severity and impact of the non-compliance, and identify the root cause and possible remediation actions12. References 1: How to Create a Patch Management Policy: Complete Guide 2: Free Patch Management Policy Template (+Examples)