Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?
What is the MAIN purpose of an organization's internal IS audit function?
An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?
An IS auditor determines elevated administrator accounts for servers that are not properly checked out and then back in after each use. Which of the following is the MOST appropriate sampling technique to determine the scope of the problem?