IIA-CIA-PART2 · Question #36
A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the…
The correct answer is B. 1 and 3. The chief audit executive (CAE) should meet with the chief IT officer to discuss the incident, the investigation, and any control improvements that will be implemented (1). Additionally, developing an appropriate audit program with the IT auditor to review the organization's…
Question
Options
- A1 and 2
- B1 and 3
- C2 and 4
- D3 and 4
How the community answered
(16 responses)- A25% (4)
- B56% (9)
- C13% (2)
- D6% (1)
Explanation
The chief audit executive (CAE) should meet with the chief IT officer to discuss the incident, the investigation, and any control improvements that will be implemented (1). Additionally, developing an appropriate audit program with the IT auditor to review the organization's Internet-based sales process and key controls (3) is a proactive approach to ensure future incidents are prevented and to enhance the organization's security posture.
Topics
Community Discussion
No community discussion yet for this question.