An IS auditor has completed the fieldwork phase of a network security review and is preparing the initial draft of the audit report. Which of the following findings should be ranked as the HIGHEST risk?
- Network penetration tests are not performed.
- The network firewall policy has not been approved by the information security officer.
- Network firewall rules have not been documented.
- The network device inventory is incomplete.
Reveal Solution Next Question