CompTIA Security+ SY0-701 Practice Question
What is the primary purpose of maintaining evidence from internal audits within a company's security governance framework?
To increase transparency with external stakeholders and the public regarding internal security practices
To advertise the company's security posture and capabilities to potential clients and customers
To serve as a replacement for annual external audits by providing a sufficient level of assurance
To document findings and actions taken, which supports the accountability and effectiveness of the audits