"A certification audit has discovered that security risk assessments are not being carried out within the stipulated timeframes. <br> She has indicated that this does not comply with ISO/IEC 20000-1 standard.<br>
What justifies this deviation from the norm?"
-
A
Security risk assessments should be performed as agreed
-
B
Security risk assessments are not addressed in the ISO/IEC 20000
-
C
Security risk assessments shall be performed at least annually
-
D
Security risk assessments shall be performed at planned intervals