Podcast
Questions and Answers
What should be done with intentionally bypassed I&T-related risk?
What should be done with intentionally bypassed I&T-related risk?
- Document it separately for future reference
- Ignore it completely
- Exclude it from the risk assessment process
- Include it in the risk report (correct)
What is a risk map?
What is a risk map?
- A spreadsheet for tracking financial risks
- A verbal description of potential risks
- A written report on historical risk trends
- A graphic tool for ranking and displaying risk by defined ranges for frequency and impact (correct)
What can observing a process help?
What can observing a process help?
- Identify situations in which documented processes and controls are not being followed (correct)
- Recording important events that occur on a system
- Analysis of enterprise processes and incidents
- Providing an evaluation of control effectiveness