Question 1.
A compliance standard dictates that your organization requires every visitor to your office location to sign in and sign out using a visitor management log. To assess the effectiveness of the control, previous Governance team members would review the log once a month to make sure visitors are signing in and out. Is this an effective control measurement?
Yes
No
Question 2
You have just discovered that one of your critical security controls is not functioning correctly. You have created a report on the control and your findings which show that the control is not operating as expected. Who should you share the report with initially? Check all that apply?
IT Steering Committee or Risk Management Committee
Control owner
The organization's Board of Directors
Customers
Next Concept