An IS auditor is planning to review the security of a financial application for a large company with several locations worldwide. The application system is made up of a web interface, a business logic layer and a database layer. The application is accessed locally through a LAN and remotely through the Internet via a virtual private network (VPN) connection.
3. Given that the application is accessed through the Internet, how should the auditor determine whether to perform a detailed review of the firewall rules and VPN configuration settings?
Group of answer choices
a. Documented risk analysis
b. Availability of technical expertise
c. Approach used in previous audit
d. IS auditing guidelines and best practices