IIA Business Knowledge for Internal Auditing IIA-CIA-Part3 Question # 10 Topic 2 Discussion

IIA Business Knowledge for Internal Auditing IIA-CIA-Part3 Question # 10 Topic 2 Discussion

IIA-CIA-Part3 Exam Topic 2 Question 10 Discussion:
Question #: 10
Topic #: 2

An internal auditor has completed the fieldwork of an assurance engagement on the organization's business continuity. The most significant finding is that business requirements were left up to the IT function to decide and implement. As a result, the time to recovery for some critical systems following a disruption is too long, while recovery time of non-critical systems is needlessly prioritized at a significant cost. Which of the following is the most appropriate recommendation to include in the engagement report?


A.

Management of business units should review and correct the recovery targets


B.

Conduct an IT function review and correct the recovery targets


C.

Management of the IT function should ensure that the business continuity plan is more realistic


D.

Ensure that in the future business requirements are set by the management of business units


Get Premium IIA-CIA-Part3 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.