Question: Read the article Security Controls that Work by Dwayne Melancon in the 2007 Issue, Volume 4 of the Information Systems Control Journal (available www.isaca.org/Journal/Past-Issues/2007/Volume-4 /Pages/Security-Controls-That-Work1.aspx).

Read the article “Security Controls that Work” by Dwayne Melancon in the 2007 Issue, Volume 4 of the Information Systems Control Journal (available www.isaca.org/Journal/Past-Issues/2007/Volume-4 /Pages/Security-Controls-That-Work1.aspx). Write a report that answers the following questions:
1. What are the differences between high-performing organizations and medium- and low-performing organizations in terms of normal operating performance? Detection of security breaches? Percentage of budget devoted to IT?
2. Which controls were used by almost all high-performing organizations, but were not used by any low- or medium-performers?
3. What three things do high-performing organizations never do?
4. What metrics can an IT auditor use to assess how an organization is performing in terms of change controls and change management? Why are those metrics particularly useful?

Step by Step Solution

3.34 Rating (148 Votes )

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock

1 Differences between highperforming and medium and lowperforming organizations are that highperforming organizations the article lists the following Completed eight times as many projects Managed six ... View full answer

blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Document Format (1 attachment)

Word file Icon

373-B-A-I-S (4872).docx

120 KBs Word File

Students Have Also Explored These Related Accounting Questions!