Before an information-security policy can publish, Legal and IT Security must approve. What should be configured?
Select an answer to reveal the explanation.
Short Explanation
Publishing a policy without Legal and Security is like shipping code without review. Put both in the lifecycle approval path before publish. Optional comments, peer-only review, or approve-after-it-is-live are backwards.
Full Explanation
Policy lifecycle workflows gate publication behind designated approvers. Configuring approvals that include Legal and IT Security ensures legal and security stakeholders accept the policy before it becomes effective. Immediate publish, peer-only paths, or post-publication email approvals weaken controlled policy release in IRM.