What is the FIRST element that must be evaluated in a security governance program?
An organization’s business objectives and strategy
Review of Information Technology (IT) and technical controls
Review of organization’s Information Technology (IT) security policies
An organization’s utilization of resources
Submit