Which of the following should be of GREATEST concern to an IS auditor assessing an organization ' s patch management program?
Patches are deployed from multiple deployment servers.
There is no process in place to scan the network to identify missing patches.
Patches for medium- and low-risk vulnerabilities are omitted.
There is no process in place to quarantine servers that have not been patched.
Submit