Exam Study Flashcards
Who approves the audit charter?
The highest level of management/ top management
Who carries out the audit process as per approved audit charter?
Chief Audit Officer (CAO)
Which groups should be independent of the audit charter?
IS department and IT steering committee
Why does the IS Auditor review the organization chart?
To understand the responsibilities and authority of individuals in the organization/ identify if there is SOD in place
What is the best configuration of the firewall rule base?
deny all traffic and allow specific traffic
What does an auditor look for when reviewing a firewall?
how effective is the firewall at enforcing the security policy
When implementing a firewall what error is most likely to occur?
Wrong configuration of the access lists.
The online auditing technique that identifies excess inventory for the previous year
Generalized audit software