Question: Standards such as NIST can provide a baseline control framework that can be used by the auditor to assess the existing internal controls over information
Standards such as NIST can provide a baseline control framework that can be used by the auditor to assess the existing internal controls over information security in an organization. It can be used to conduct an IT risk assessment over information security and as a complement to the standards for professional performance of internal auditing or International Professional Practices Framework (IPPF)*.
How NIST and IPPF can be used together by an IT Auditor in the practice of internal auditing.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
