An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management?
A. Engage an independent third party to validate the disputed findings
B. Restructure audit reporting lines to the board or audit committee
C. Expand testing scope and increase assessment frequency
D. Require management sign-off attestations on every audit report
(Explain your answer for more points in the comments!)