QuestionQ144

Information Systems Operations and Business Resilience

While reviewing an organization’s network threat-response process, an IS auditor observed that most alerts were closed without being resolved.

Management stated that these alerts could not be acted on because they lacked actionable intelligence, and that the support team is therefore permitted to close them. What is the BEST way for the auditor to address this situation?

Explanation

A large volume of alerts closed as unactionable can indicate an ineffective threat-response process even when the current policy permits those closures. Enhancing the policy and improving threat-awareness training strengthens the ability to assess, enrich, and appropriately respond to alerts.

Community Discussion

No comments yet. Be the first to start the discussion!