Correct option is C
The proper sequence of benefits available to an Information System Auditor who uses CATT is as follows:
1.
Check susceptibility to threat (A): Using CATT, the auditor can assess the system's susceptibility to threats and risks, particularly in the context of cloud-based or online accounting systems. It helps in identifying potential vulnerabilities and evaluating the effectiveness of security measures.
2.
Evaluating the system (B): CATT enables the auditor to assess and evaluate the effectiveness and efficiency of the information system. This involves analyzing the system's controls, processes, and data.
3.
Data security (C): CATT can assist in evaluating data security measures and identifying vulnerabilities in the information system. It helps in assessing the adequacy of controls in place to protect sensitive data from unauthorized access, modification, or disclosure.
4.
Bolsters controls (D): CATT can strengthen internal controls by providing automated testing and monitoring capabilities. It helps the auditor to identify control weaknesses, monitor compliance with policies and procedures, and detect any fraudulent activities.
5.
Develop IT Governance (E): CATT supports the development and implementation of IT governance frameworks and practices. It allows the auditor to assess the alignment of IT strategies with the organization's objectives and evaluate the overall IT governance structure.
Therefore, the correct sequence is (c) A, B, C, D, E: Check susceptibility to threat, Evaluating the system, Data security, Bolsters controls, and Develop IT Governance.