During an information security audit, an auditor discovers that the current disaster recovery plan was developed three years ago but never tested. There have been significant changes to information systems since the plan was developed. The auditor should:
- Ask management to test the recovery plan immediately.
- Recommend that management and users update and test the recovery plan.
- Update the recovery plan for management as part of the review.
- Review the recovery plan and report weaknesses to management.
Reveal Solution Next Question