View all detail and faqs for the IIA-CIA-Part3-3P exam
Which of the following are appropriate functions for an IT steering committee?
1) Assess the technical adequacy of standards for systems design and programming.
2) Continually monitor of the adequacy and accuracy of software and hardware in use.
3) Assess the effects of new technology on the organization`s IT operations.
4) Provide broad oversight of implementation, training, and operation of new systems.
Organizational activities that complement each other and create a competitive advantage are called a:
Which of the following is true regarding an organization's relationship with external stakeholders?
Which of the following statements are true regarding the use of heat maps as risk assessment tools?
1. They focus primarily on known risks, limiting the ability to identify new risks.
2. They rely heavily on objective assessments and related risk tolerances.
3. They are too complex to provide an easily understandable view of key risks.
4. They are helpful but limited in value in a rapidly changing environment.
Which of the following statements is correct regarding risk analysis?
The internal audit activity completed an initial risk analysis of the organization's data storage center and found several areas of concern. Which of the following is the most appropriate next step?