Okay, I think I've got a handle on this. The key is to identify which option best describes the internal audit activity's responsibility in assessing the organization's IT governance. I'll weigh the options and select the most appropriate one.
Assigning quantitative values to qualitative metrics could be a good way to make the risk profile more data-driven, but I'm not sure if that's the "BEST" approach based on the question.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Phil
4 months agoJin
4 months agoJeniffer
4 months agoYoulanda
4 months agoEttie
4 months agoKimbery
5 months agoEden
5 months agoHolley
5 months agoRobt
5 months agoTijuana
5 months agoPaz
5 months agoNohemi
5 months ago