Question 91

An organization decides to establish a formal incident response capability with clear roles and responsibilities facilitating centralized reporting of security incidents. Which type of control is being implemented?
  • Question 92

    Which control type would provide the MOST useful input to a root cause analysis?
  • Question 93

    Which of the following audit procedures would be MOST conclusive in evaluating the effectiveness of an e-commerce application system's edit routine?
  • Question 94

    A data center's physical access log system captures each visitor's identification document numbers along with the visitor's photo. Which of the following sampling methods would be MOST useful to an IS auditor conducting compliance testing for the effectiveness of the system?
  • Question 95

    Which of the following BEST indicates that an organization has effective governance in place?