Valid IIA-CIA-Part2-CN Dumps shared by ExamDiscuss.com for Helping Passing IIA-CIA-Part2-CN Exam! ExamDiscuss.com now offer the newest IIA-CIA-Part2-CN exam dumps, the ExamDiscuss.com IIA-CIA-Part2-CN exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com IIA-CIA-Part2-CN dumps with Test Engine here:
一家在網路上銷售大部分產品的大型零售組織遭遇了電腦駭客攻擊事件。首席 IT 長立即調查該事件並得出結論,該嘗試沒有成功。首席審計執行長 (CAE) 在與 IT 審計員的一次隨意交談中得知了攻擊。 CAE 應採取下列哪些行動? 1. 與首席 IT 長會面,討論因安全漏洞(如果有)而實施的報告和控制改進。 2. 立即將安全漏洞告知審計委員會主席,因為到目前為止只有首席 IT 長知道該事件。 3. 與 IT 審計員會面,制定適當的審計計劃,以審查組織基於 Internet 的銷售流程和關鍵控制。 4. 將該事件納入提交給審計委員會的下一個季度報告中。
Correct Answer: B
The chief audit executive (CAE) should meet with the chief IT officer to discuss the incident, the investigation, and any control improvements that will be implemented (1). Additionally, developing an appropriate audit program with the IT auditor to review the organization's Internet-based sales process and key controls (3) is a proactive approach to ensure future incidents are prevented and to enhance the organization's security posture. Reference: = IIA Standard 2120 - Risk Management and IIA Standard 2201 - Planning Considerations.