While executing follow-up activities, an IS auditor is concerned that management has implemented corrective actions that are different from those originally discussed and agreed with the audit function. In order to resolve the situation, the IS auditor's BEST course of action would be to:
During a disaster recovery audit, an IS auditor finds that a business impact analysis (BIA) has not been performed. The auditor should FIRST
Which of the following is the BEST source of information for assessing the effectiveness of IT process monitoring?
Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?
Which of the following is MOST important with regard to an application development acceptance test?
An IS auditor who was instrumental in designing an application is called upon to review the application. The auditor should:
The decision to accept an IT control risk related to data quality should be the responsibility of the:
Which of the following is the BEST way to address segregation of duties issues in an organization with budget constraints?