During an identity and access management audit, an IS auditor discovers that the engagement audit plan excludes testing of controls governing third-party access. What would be the auditor's BEST course of action?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion