In the PDCA model, what is the primary risk of skipping the 'Check' phase?
-
A
The ISMS will become too expensive to operate
-
B
Ineffective controls may go undetected, leaving the organization exposed
-
C
New employees will not receive security training
-
D
The risk treatment plan cannot be updated