Which of the following is the auditor’s BEST course of action?
An IS auditor suspects an organization’s computer may have been used to commit a crime.
Which of the following is the auditor’s BEST course of action?
A . Examine the computer to search for evidence supporting the suspicions.
B . Advise management of the crime after the investigation.
C . Contact the incident response team to conduct an investigation.
D . Notify local law enforcement of the potential crime before further investigation.
Answer: C
Explanation:
The IS auditor’s best course of action if they suspect an organization’s computer may have been used to commit a crime is to contact the incident response team to conduct an investigation. The incident response team is a group of experts who are responsible for responding to security incidents, such as data breaches, ransomware attacks, or cybercrimes. The incident response team can help to preserve and collect digital evidence, determine the scope and impact of the incident, contain and eradicate the threat, and restore normal operations. The IS auditor should not examine the computer themselves, as they may inadvertently alter or destroy potential evidence, or compromise the chain of custody. The IS auditor should also not notify local law enforcement before further investigation, as this may escalate the situation unnecessarily or interfere with the internal investigation process. The IS auditor should advise management of the crime after the investigation, or as soon as possible if there is an imminent risk or legal obligation to do so.
Latest CISA Dumps Valid Version with 2694 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund