QuestionQ44

Protection of Information Assets

An IS auditor observes that application super-user activity was not captured in the system logs. What is the auditor’s BEST course of action?

Explanation

An auditor should investigate the reason super-user activity was not logged to establish the cause, scope, and control impact of the condition. This provides the evidence needed to support an appropriate audit finding, escalation, or remediation recommendation.

Community Discussion

No comments yet. Be the first to start the discussion!