CISA Certified Information Systems Auditor – Question0510

An IS auditor can BEST help management fulfill risk management responsibilities by:

A.
highlighting specific risks not being addressed.
B. ensuring the roles for managing IT risk are defined.
C. developing an IT risk management framework.
D. adopting a mechanism for reporting issues.

Correct Answer: C