The correct answer is C. Ensure management has identified the data and where it resides.
Before assessing the organization's ability to secure its data, the IS auditor must first ensure that management has:
- Identified the data that needs to be protected
- Determined where the data is stored, processed, and transmitted
- Recognized the data's importance and value to the organization
This step is essential because it provides a foundation for the rest of the assessment. Without a clear understanding of what data needs to be protected and where it resides, it is impossible to effectively secure it.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
jan1234
Highly Voted 4 months, 1 week agoRS66
Most Recent 3 months ago