What is the PRIMARY reason an IS auditor would recommend using key risk indicators (KRIs)?
KRIs provide early warning of changes in risk exposure and enable monitoring of trends in the risk profile. ISACA states that KRIs and their thresholds enable monitoring of changes in risk, and that analyzing KRIs identifies changes or trends in the IT risk profile.
Community Discussion