8.17

From Corrective Action Plan AZ
Revision as of 22:31, 15 August 2026 by Neil thibodaux (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.17 - Management considers information security risk factors, which may include the following:

  • the complexity of the entity's information technology;
  • new or emerging technologies;
  • information technology that may be outdated or incompatible with new technologies;
  • decentralized operating systems and communications networks;
  • external-party access to the entity's operating systems and communications networks;
  • information technology personnel not having the knowledge, skills, or abilities to maintain the entity's information technology and respond to related risks; and
  • personnel being unfamiliar with technology and related risks.

>>>Navigational Buttons<<<


No Examples