新しい電子商取引システムのデータベース制御をレビューしている IS 監査人が、データベース構成のセキュリティ上の弱点を発見しました。IS 監査人が次に取るべき行動は次のどれですか。
正解:A
When an IS auditor discovers a security weakness in the database configuration, the next course of action should be to identify existing mitigating controls. This involves assessing whether any controls are already in place to address the weakness and mitigate the risk. Understanding the current state of controls helps the auditor determine the severity of the issue and whether additional corrective actions are necessary1. References: 1(https://www.isaca.org/resources/insights-and-expertise/audit-programs-and-tools)