Acceptable levels of information security risk should be determined by:
A. legal counsel.
B. security management.
C. external auditors.
D. die steering committee.
A. legal counsel.
B. security management.
C. external auditors.
D. die steering committee.