Which of the following offers the MOST reliable information for ensuring that a newly acquired company has appropriate IT controls in place?
An information system audit independently evaluates the design and operating effectiveness of IT controls, providing the most reliable assurance that appropriate controls are in place. Risk assessments identify exposures, while vulnerability assessments and penetration tests focus on technical weaknesses rather than the overall control environment.
Community Discussion