During an information systems audit, which of the following is NOT a valid risk assessment method?
Risk ranking and prioritization
Statistical sampling
Overlook minor misbehaviors
Impose harsh punishments for any infraction

Information Systems Exercises are loading ...