Greg Oct 13, 2021 3:41 pm I'm having a hard time reconciling the grain silo scenario with Principle 1. If the IT systems of the grain silo go down, that won't impact the ability to do a financial audit, but that could be a "business risk" as mentioned in Principle 1, because, without the IT systems, the business may not be able to function. So are the grain silo IT systems in or out of scope? Reply
spiritflare01 Jan 5, 2019 8:48 pm Excellent high level summary - written in a easy to understand style; thank you! If possible could you do a follow up article on identifying and testing key controls (high level) such as TOD/TOE ? Thanks! Reply