An IS auditor is developing a risk-based audit plan. Which of the following is the FIRST step the auditor should perform?
-
A
Identify the organization's critical assets and business processes.
-
B
Review the findings and workpapers from the previous year's audit.
-
C
Develop the audit scope and objectives for specific high-risk areas.
-
D
Interview senior management to understand their perspective on risk.