GAQM
CPEH-001 · Question #456
During a security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
The correct answer is A. Identify and evaluate existing practices. The auditor should first evaluated existing policies and practices to identify problem areas and
Introduction to Ethical Hacking and Information Security
Question
During a security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
Options
- AIdentify and evaluate existing practices
- BCreate a procedures document
- CConduct compliance testing
- DTerminate the audit
How the community answered
(66 responses)- A83% (55)
- B9% (6)
- C3% (2)
- D5% (3)
Explanation
The auditor should first evaluated existing policies and practices to identify problem areas and
Topics
#security audit#IS auditing#security procedures#compliance
Community Discussion
No community discussion yet for this question.