A new regulation requires organizations to appoint a Data Protection Officer (DPO). Which policy document should be updated FIRST to reflect this governance change?
-
A
Incident response plan
-
B
Information security charter or governance policy
-
C
Vulnerability management policy
-
D
Network access control policy