Question 431

An IS auditor is reviewing enterprise governance and finds there is no defined organizational structure for technology risk governance. Which of the following is the GREATEST concern with this lack of structure?
  • Question 432

    An IS auditor is reviewing an organization's risk management program. Which of the following should be the PRIMARY driver of the enterprise IT risk appetite?
  • Question 433

    Which of the following is the BEST use of a maturity model in a small organization?
  • Question 434

    During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor's BEST course of action?
  • Question 435

    A financial services organization is developing and documenting business continuity measures. In which of the following cases would an IS auditor MOST likely raise an issue?