The auditor should first determine whether there is a documented business need for the vendor employees’ remote access. Access should be granted only when justified by a legitimate operational requirement and supported by authorization. Once the business need is confirmed, the auditor can assess whether access is appropriately limited, monitored, and revoked when no longer needed. Read-only access may still be excessive if no business need exists. Immediately identifying who should remove access is premature without determining whether access is valid. Device management is important but secondary to confirming need and authorization. Internal auditors reviewing third-party access should evaluate business justification, approval, least privilege, authentication, monitoring, and periodic recertification. Therefore, Option A is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit