An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates
4 percent noncompliance?
Select an option, then click Submit answer.
-
○
The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
-
○
The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
-
○
The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
-
○
The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.