During an IS audit, an auditor discovers that a control is functioning as intended but the risk it mitigates has already been accepted by management. What is the BEST course of action?
-
A
Report the control as effective and move on
-
B
Document the accepted risk and note the control as redundant in the report
-
C
Recommend removing the control immediately
-
D
Escalate to the board of directors