Which of the following deficiencies identified during a review of an organization's cybersecurity policy should be of MOST concern?
Correct Answer: D
The policy has not been approved by the organization's board should be of most concern, as it indicates a lack of governance and oversight for the organization's cybersecurity posture. The board is ultimately responsible for setting the strategic direction, objectives, and risk appetite of the organization, and for ensuring that the cybersecurity policy aligns with them. Without the board's approval, the policy may not reflect the organization's vision, mission, values, and culture, and may not be communicated, implemented, or enforced effectively. The board's approval also demonstrates the commitment and support of the senior management for the cybersecurity program, and enhances the accountability and responsibility of the stakeholders involved.
References:
*ISACA, Essential Functions of a Cybersecurity Program1
*ISACA, Cybersecurity: Based on the NIST Cybersecurity Framework2