Question
Read the article Security Controls that Work by Dwayne Melancon in the 2007 Issue, Volume 4 of the Information Systems Control Journal (available http://www.isaca.org/Journal/Past-Issues/2007/Volume-4 /Pages/Security-Controls-That-Work1.aspx).
Read the article "Security Controls that Work" by Dwayne Melancon in the 2007 Issue, Volume 4 of the Information Systems Control Journal (available http://www.isaca.org/Journal/Past-Issues/2007/Volume-4 /Pages/Security-Controls-That-Work1.aspx). Write a report that answers the following questions:
1. What are the differences between high-performing organizations and medium- and low-performing organizations in terms of normal operating performance? Detection of security breaches? Percentage of budget devoted to IT?
2. Which controls were used by almost all high-performing organizations, but were not used by any low- or medium-performers? 3. What three things do high-performing organizations never do?
4. What metrics can an IT auditor use to assess how an organization is performing in terms of change controls and change management? Why are those metrics particularly useful?
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started