QuestionQ1418

Governance

A large organization recently reorganized its IT department and decided to outsource certain functions. What should the IT department’s control owners do?

  • A Determine whether risk responses still effectively address risk.
  • B Conduct risk classification for associated IT controls.
  • C Perform vulnerability and threat assessments.
  • D Analyze and update IT control assessments.
Explanation

Changes in organizational structure and the outsourcing of IT functions can alter control ownership, operation, evidence, and reliance on third parties. IT control assessments should therefore be analyzed and updated so the controls continue to accurately reflect the changed operating environment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!