An acquisition closes in 30 days, and the deal team wants the acquired staff in shared systems on day one. How that firm grants, reviews, and removes access is unknown. What should the CISO do FIRST? A. Federate both identity providers for day one sign-in B. Assess the acquired firm's identity governance and access lifecycle C. Issue temporary parent directory accounts to acquired staff D. Require multifactor authentication on acquired accounts before connecting (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!