An IS auditor follows up on a recent security incident and finds the incident response was not adequate. Which of the following findings should be considered
MOST critical?
- The attack could not be traced back to the originating person.
- The attack was not automatically blocked by the intrusion detection system (IDS).
- Appropriate response documentation was not maintained.
- The security weakness facilitating the attack was not identified.
Reveal Solution Next Question