Question 446

During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor's BEST course of action?
  • Question 447

    A small startup organization does not have the resources to implement segregation of duties. Which of the following would be the MOST effective compensating control?
  • Question 448

    Previous audits have found that a large organization has had a number of segregation of duties conflicts between various roles, and the IT governance committee has asked the audit function for guidance on how to address this issue. Which of the following is the BEST recommendation?
  • Question 449

    Which of the following is the BEST reason for an IS auditor to emphasize to management the importance of using an IT governance framework?
  • Question 450

    Stress testing should ideally be carried out under a: