KILL-04

更新时间: 试题数量: 购买人数: 提供作者:

有效期: 个月

章节介绍: 共有个章节

收藏
搜索
题库预览
The Widget company decided to take their company public and while they were in the process of doing so had an externa auditor come and look at their company. As part of the external audit they brought in an technology expert, who incidentally was a new CISSP. The auditor's expert asked to see their last risk analysis from the technology manager. The technology manager did not get back to him for a few days and then the Chief Financial Officer gave the auditors a 2 page risk assesment that was signed by both the Chief Financial Officer and the Technology Manager. While reviewing it, the auditor noticed that only parts of their financial data were being backed up on site and no where else; the Chief Financial Officer accepted the risk of only partial financial data being backed up with no off-site copies available. Who owns the risk with regards to the data that is being backed up and where it is stored? Widget公司决定将其公司上市,在上市过程中,一名externa审计员来检查他们的公司。作为外部审计的一部分,他们请来了一位技术专家,顺便说一句,他是一位新的CISSP。审计专家要求技术经理查看他们最后的风险分析。技术经理有几天没有回复他,然后首席财务官给了审计员一份两页的风险评估报告,由首席财务官和技术经理签字。审核时,审计人员注意到,只有部分财务数据在现场备份,其他地方没有备份;首席财务官接受了只备份部分财务数据而没有场外副本的风险。谁负责备份的数据及其存储位置的风险?