サイバー攻撃を受けた組織が、影響を受けたユーザーのコンピュータのフォレンジック分析を実行しています。このプロセスを確認する情報システム監査人が最も懸念すべき事項は次のどれですか?
正解:C
The chain of custody has not been documented is a finding that should be of greatest concern for an IS auditor reviewing a forensic analysis process of an organization that has suffered a cyber attack. The chain of custody is a record of who handled, accessed, or modified the evidence during a forensic investigation.
Documenting the chain of custody is essential to preserve the integrity, authenticity, and admissibility of the evidence in a court of law. The other options are less concerning findings that may not affect the validity or reliability of the forensic analysis process. References:
* CISAReview Manual (Digital Version), Chapter 7, Section 7.51
* CISA Review Questions, Answers &Explanations Database, Question ID 220