あるテクノロジー企業の内部監査部門は、ソフトウェア開発プロセスのセキュリティを評価するための一連の業務を実施する予定です。これらの業務を成功裏に遂行するために、内部監査部門はどのような能力を備えているべきでしょうか?
正解:B
Comprehensive and Detailed Explanation:
Software development security requires internal auditors to understand change management processes (B) - how updates, patches, and new code are introduced and controlled to prevent vulnerabilities. While IT general controls (A) are important, they are broader (e.g., access, backup, operations). Fluency in programming languages (D) and proficiency in design software (C) are too technical and unnecessary for audit. Instead, auditors need to understand how changes are authorized, tested, and implemented, ensuring that the development process follows security and governance standards. According to Standard 1210 - Proficiency, internal auditors must have or obtain sufficient knowledge to evaluate relevant risks, making change management competency most critical.