Which of the following should an internal auditor check for first when conducting an audit of the organization's risk management program?
Policies and procedures
Asset management
Vulnerability assessment
Business impact analysts
Submit