An IS auditor reviewing the database controls for a new e-commerce system discovers a security weakness in the database configuration. Which of the following should be the IS auditor's NEXT course of action?
Wait, we can't just start exploiting the weakness, that's like trying to beat a video game by cheating. I'd go with option C - assist in drafting corrective actions to fix this properly.
Hmm, I think option A is the way to go. Let's see if there are any existing controls that can mitigate the issue before we go nuclear and disclose it to the higher-ups.
Option B all the way! Transparency is key, and senior management needs to know about this weakness ASAP. Once they're aware, we can work on the corrective actions.
Clearly, option D is a big no-no. We don't want to create more problems than we already have. I'd say B and C are the way to go - disclose it to management and help them fix it.
Pearline
7 months agoHuey
6 months agoDalene
6 months agoLonny
7 months agoErnestine
7 months agoWinfred
6 months agoErick
6 months agoGeorgiann
7 months agoJacklyn
7 months agoColetta
7 months agoRoslyn
7 months agoAmber
7 months agoCortney
6 months agoTenesha
7 months agoMiles
7 months agoHannah
8 months agoMertie
8 months ago