セキュリティ監査中、IS 監査人は、エンタープライズ侵入防止システム (IPS) から取得したログ エントリを確認する任務を負います。監査人が、IPS 構成のエラーを示す可能性のある一連のログ イベントを見逃す可能性に関連するリスクの種類はどれですか。
正解:B
The type of risk associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration is detection risk. Detection risk is the risk that the auditor's procedures will not detect a material misstatement or error that exists in an assertion or a control. Detection risk can be affected by factors such as the nature, timing, and extent of the audit procedures, the quality and sufficiency of the audit evidence, and the auditor's professional judgment and competence. Detection risk can be reduced by applying appropriate audit techniques, such as sampling, testing, observation, inquiry, and analysis. References:
* CISA Review Manual (Digital Version)
* CISA Questions, Answers & Explanations Database