An auditor has completed an audit of an organization’s use of a tool that generates SSL certificates for its external web sites. The auditor has determined that key management procedures are insufficient and that split custody of the key generation procedure is required. How might this be implemented?

🎲 Try a Random Question  |  Total Questions in Quiz: 82  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
CISA Domain 5: Protection of Information Asset — practice the complete quiz, review flashcards, or try a random question.


An auditor has completed an audit of an organization’s use of a tool that generates SSL certificates for its external web sites. The auditor has determined that key management procedures are insufficient and that split custody of the key generation procedure is required. How might this be implemented?