Question 431
An IS auditor is reviewing enterprise governance and finds there is no defined organizational structure for technology risk governance. Which of the following is the GREATEST concern with this lack of structure?
Question 432
An IS auditor is reviewing an organization's risk management program. Which of the following should be the PRIMARY driver of the enterprise IT risk appetite?
Question 433
Which of the following is the BEST use of a maturity model in a small organization?
Question 434
During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor's BEST course of action?
Question 435
A financial services organization is developing and documenting business continuity measures. In which of the following cases would an IS auditor MOST likely raise an issue?
