An internal auditor is reviewing physical and environmental controls for an IT organization. Which control activity should not be part of this review?
In order to provide useful information for an organization's risk management decisions, which of the following factors is least important to assess?