Question 399:
An IS auditor reviewing a financial organization`s identity management solution found that some critical business applications do not have identified owners. Which of the following should the auditor do NEXT?
Answer options:
A. Request a business risk acceptance. B. Discuss the issue with the auditee. C. Write a finding in the audit report. D. Revoke access rights to the critical applications.