This is a dedicated watch page for a single video.
During an IS audit, an IS auditor discovers that management's risk assessment process lacks clear criteria for risk evaluation and prioritization. What should be the IS auditor's next course of action?