QuestionQ180

Governance

Which of the following offers the MOST reliable information for ensuring that a newly acquired company has appropriate IT controls in place?

  • A Vulnerability assessment
  • B Information system audit
  • C Penetration testing
  • D IT risk assessment
Explanation

An information system audit independently evaluates the design and operating effectiveness of IT controls, providing the most reliable assurance that appropriate controls are in place. Risk assessments identify exposures, while vulnerability assessments and penetration tests focus on technical weaknesses rather than the overall control environment.

Community Discussion

No comments yet. Be the first to start the discussion!