nerdexam
EC-Council

312-50V10 · Question #746

During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

The correct answer is D. Identify and evaluate existing practices. When an IS auditor finds no documented security procedures, the correct step is to identify and evaluate whatever informal or undocumented practices may currently exist before drawing conclusions.

Information Security and Ethical Hacking Fundamentals

Question

During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

Options

  • ACreate a procedures document
  • BTerminate the audit
  • CConduct compliance testing
  • DIdentify and evaluate existing practices

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    10% (4)
  • D
    79% (31)

Why each option

When an IS auditor finds no documented security procedures, the correct step is to identify and evaluate whatever informal or undocumented practices may currently exist before drawing conclusions.

ACreate a procedures document

Creating procedures is management's responsibility, not the auditor's - doing so would impair auditor independence.

BTerminate the audit

Terminating the audit is premature because the absence of documented procedures does not mean controls or practices are absent.

CConduct compliance testing

Compliance testing cannot be meaningfully performed without first understanding what practices or standards exist to test against.

DIdentify and evaluate existing practicesCorrect

An auditor's role is to assess the actual state of controls, which includes determining whether compensating or informal practices exist even in the absence of formal documentation. Identifying and evaluating existing practices allows the auditor to form an accurate risk opinion and provide meaningful recommendations rather than assuming a complete absence of controls. This aligns with ISACA auditing standards that require evidence gathering before conclusions are reached.

Concept tested: IS auditor response to missing documented procedures

Source: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-1/the-role-of-the-it-auditor

Topics

#IS audit#security procedures#compliance testing#risk management

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice