Understanding the types of databases being used within the organization provides essential context for planning the review. This includes identifying the databases' platforms, vendors, versions, and configurations. Such information is crucial for determining the scope of the review (Option A), as it helps the auditor understand the potential risks and vulnerabilities associated with each type of database.
C. Evaluate the types of databases being used.
CISA Study Guide 27th: Tycpical Audit Process Steps bys Phase
Planning Phase (Determine audit subject --> Define audit objective --> Set audit scope...)
Setting scope is very important. After deciding on the scope, you need to find the important databases within the scope. Databases outside the scope are not important.
During the preliminary planning phase of a database security review, an IS auditor should first determine which databases will be in scope. This allows the auditor to focus their efforts on the specific databases that are relevant to the organization's security posture and objectives.
before looking at which databases will be in scope, first understand the types of databases being used.
upvoted 1 times
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Swallows
1 month, 1 week ago5b56aae
2 months, 3 weeks agoMJORGER
4 months agocrowsaint
9 months, 4 weeks agoMohamedAbdelaal
1 year, 2 months agocidigi
11 months agoSBD600
1 year, 2 months agoChaBum
4 months, 2 weeks ago