QuestionQ85

Information System Auditing Process

A new regulation has been enacted that requires specific information-security practices to protect customer data. Which of the following would be MOST useful for an IS auditor to review when auditing against the regulation?

Explanation

A compliance gap analysis directly compares the regulation’s requirements with implemented controls, identifies unmet requirements, and documents remediation needs. It therefore provides the most relevant evidence for an audit of compliance with the new regulation.

Community Discussion

No comments yet. Be the first to start the discussion!