Question 331

An IS auditor conducts a review of a third-party vendor's reporting of key performance indicators (KPIs) Which of the following findings should be of MOST concern to the auditor?
  • Question 332

    During an audit, an IS auditor notices that the IT department of a medium-sized organization has no separate risk management function, and the organization's operational risk documentation only contains a few broadly described IT risks. What is the MOST appropriate recommendation in this situation?
  • Question 333

    In order for a firewall to effectively protect a network against external attacks, what fundamental practice must be followed?
  • Question 334

    When should application controls be considered within the system-development process?
  • Question 335

    Which of the following is the PRIMARY advantage of parallel processing for a new system implementation?