A newly appointed information security manager discovers that business units independently procure cloud services without IT involvement. What is the BEST first step?
-
A
Immediately block all unauthorized cloud services
-
B
Conduct a risk assessment of existing shadow IT
-
C
Establish a cloud governance policy with business stakeholder input
-
D
Report the violations to senior management for disciplinary action