Question 486

An IS auditor conducts a review of a third-party vendor's reporting of key performance indicators (KPIs).
Which of the following findings should be of MOST concern to the auditor?
  • Question 487

    The IS auditor's PRIMARY role in control self-assessment (CSA) is to:
  • Question 488

    A PRIMARY advantage of involving business management in evaluating and managing information
    security risks is that they:
  • Question 489

    When planning an internal penetration test, which of the following is the MOST important step prior to finalizing the scope of testing?
  • Question 490

    While reviewing the business continuity plan of an organization, an IS auditor observed that the organization's data and software files are backed up on a periodic basis. Which characteristic of an effective plan does this demonstrate?