A four-part, risk-based audit approach provides a framework for conducting information system audits. Performing a systems review
Question:
A four-part, risk-based audit approach provides a framework for conducting information system audits. Performing a systems review is done in which of the four parts?
a. Determine the threats (accidental or intentional abuse and damage) to which the system is exposed.
b. Identify the control procedures that management has put into place to prevent, detect, or correct the threats.
c. Evaluate whether control procedures are actually in place and if they work as intended.
d. Evaluate control weaknesses to determine their effect on the nature, timing, or extent of auditing procedures.
Fantastic news! We've Found the answer you've been seeking!
Step by Step Answer:
Related Book For
Accounting Information Systems
ISBN: 9781292220086
14th Global Edition
Authors: Marshall B. Romney, Paul John Steinbart
Question Posted: