QuestionQ17

Information System Auditing Process

While performing fieldwork, an internal IS auditor identifies a critical vulnerability in a newly deployed application. What is the auditor's BEST action?

Explanation

Critical security vulnerabilities should be promptly escalated to the responsible IT management so that remediation can begin immediately. Recording the issue in the audit report does not provide the necessary timely notification.

Community Discussion

No comments yet. Be the first to start the discussion!