A CISO discovers that a third-party vendor has access to sensitive data but is not covered by the organization's security policy. What is the BEST immediate step?
-
A
Terminate the vendor contract immediately
-
B
Issue a temporary security exception while drafting a vendor policy addendum
-
C
Apply the existing internal policy verbatim to the vendor
-
D
Notify regulators about the policy gap before taking any action