Question 331
An IS auditor conducts a review of a third-party vendor's reporting of key performance indicators (KPIs) Which of the following findings should be of MOST concern to the auditor?
Question 332
During an audit, an IS auditor notices that the IT department of a medium-sized organization has no separate risk management function, and the organization's operational risk documentation only contains a few broadly described IT risks. What is the MOST appropriate recommendation in this situation?
Question 333
In order for a firewall to effectively protect a network against external attacks, what fundamental practice must be followed?
Question 334
When should application controls be considered within the system-development process?
Question 335
Which of the following is the PRIMARY advantage of parallel processing for a new system implementation?
