An IS auditor is evaluating whether change management controls adequately protect against insider threats. The MOST effective control is:
-
A
Requiring all staff to complete annual security awareness training
-
B
Enforcing dual authorization for high-impact production changes
-
C
Conducting background checks at time of hire
-
D
Using encrypted communication channels for change notifications