While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization's inventory. Which of the following is the auditor's BEST course of action?
A.
Alert both audit and operations management about the discrepancy.
B.
Ask the asset management staff where the devices are.
C.
Make a note of the evidence to include it in the scope of a future audit.
D.
Ignore the invoices since they are not part of the follow-up.
As a cyber analyst I can say you never just ask individuals what is happening is where things are. Always assume the worst. In this case I would alert to make it known to many for investigation. I would just just ask the asset management team staff only. I could be wrong but I pick A.
option a
This action is crucial because it addresses a potential issue of asset mismanagement or oversight that could lead to financial discrepancies, compliance issues, or security vulnerabilities. By alerting both audit and operations management, the auditor ensures that the discrepancy is investigated promptly and that corrective actions can be taken to rectify the inventory records.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
blehbleh
4 weeks, 1 day agoPurpleParrot
1 month, 4 weeks agoHayati
2 months, 3 weeks ago