Big 11.11 Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

IIA Practice of Internal Auditing IIA-CIA-Part2 Question # 111 Topic 12 Discussion

IIA Practice of Internal Auditing IIA-CIA-Part2 Question # 111 Topic 12 Discussion

IIA-CIA-Part2 Exam Topic 12 Question 111 Discussion:
Question #: 111
Topic #: 12

While conducting an information security audit, an internal auditor learns that the existing disaster recovery plan is four years old and untested. The auditor also learns that in the four years since the recovery plan was implemented, the information systems have undergone extensive changes. Which of the following actions is most appropriate for the auditor to take?


A.

Inform management and request that the plan be tested immediately.


B.

Update the recovery plan for management, as part of the review.


C.

Evaluate the recovery plan and report weaknesses to management.


D.

Recommend that management and users update and test the recovery plan.


Get Premium IIA-CIA-Part2 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.