Which of the following is the PRIMARY reason an IS auditor should recommend that management create an IT risk register?
To document root causes of IT-related risk events and lessons learned
To ensure there is appropriate funding for IT risk mitigation efforts
To ensure an inventory of potential IT risks is maintained and reported
To facilitate internal audit's testing of IT-risk-related controls
Submit