Question 396

When planning a follow-up, the IS auditor is informed by operational management that recent organizational changes have addressed the previously identified risk and implementing the action plan is no longer necessary. What should the auditor do NEXT?
  • Question 397

    A third-party service provider has proposed a data loss prevention (DLP) solution. Which of the following
    MUST be in place for this solution to be relevant to the organization?
  • Question 398

    Which of the Which is the MOST effective control to reduce the risk of information leakage through social media'?
  • Question 399

    A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?
  • Question 400

    An IS auditor who is reviewing incident reports discovers that, in one instance, an important document left on an employee's desk was removed and put in the garbage by the outsourced cleaning staff. Which of the following should the IS auditor recommend to management?