An IS auditor conducting a compliance audit of a healthcare organization operating an online system that contains sensitive health care information. Which of the following should an IS auditor first review? () IT infrastructure and IS department organization chart () legal and regulatory requirements regarding data privacy () adherence to organization policies and procedures () network diagram and firewall rules surrounding the online system