Question: A four-part, risk-based audit approach provides a framework for conducting information system audits. Performing a systems review is done in which of the four parts?
A four-part, risk-based audit approach provides a framework for conducting information system audits. Performing a systems review is done in which of the four parts?
a. Determine the threats (accidental or intentional abuse and damage) to which the system is exposed.
b. Identify the control procedures that management has put into place to prevent, detect, or correct the threats.
c. Evaluate whether control procedures are actually in place and if they work as intended.
d. Evaluate control weaknesses to determine their effect on the nature, timing, or extent of auditing procedures.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
