A cybersecurity audit reveals that an organization's risk management function has the right to overrule business management decisions. Would the IS auditor find this arrangement acceptable?
The role of risk management is to provide an oversight function, ensuring that the business management's decisions align with the organization's risk appetite and strategy. If the risk management function were to overrule business management decisions, it could compromise its objectivity. This could lead to a conflict of interest and diminish the function's ability to provide unbiased oversight and measurement of business activities.
Louvenia
4 days agoLili
9 days agoEvangelina
14 days ago