Question 21

A post-implementation review of a development project concludes that several business requirements were not reflected in the software requirement specifications. Which of the following should an IS auditor recommend to reduce this problem in the future?
  • Question 22

    Which of the following is MOST important for the successful establishment of a security vulnerability management program?
  • Question 23

    An IS auditor has obtained a large complex data set for analysis. Which of the following activities will MOST improve the output from the use of data analytics tools?
  • Question 24

    Which of the following poses the GREATEST security risk when implementing acquired application systems?
  • Question 25

    Which of the following observations should be of GREATEST concern to an IS auditor reviewing a large organization's virtualization environment?