CISA Certified Information Systems Auditor – Question0877

When developing a risk-based IS audit plan, the PRIMARY focus should be on functions:

A.
considered important by IT management.
B. with the most ineffective controls.
C. with the greatest number of threats.
D. considered critical to business operations.

Correct Answer: D