An IS auditor reviews an organization's patch management policy and finds that critical security patches are applied within 72 hours on internet-facing servers but within 30 days on internal servers. What is the AUDITOR'S BEST assessment?
-
A
The policy is adequate because internal servers are not directly exposed to the internet
-
B
The tiered approach is acceptable only if internal servers are isolated from each other
-
C
The 30-day window for internal servers may be excessive and should be risk-assessed
-
D
The policy should require uniform patching timelines across all systems