312-50V10 · Question #746
During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
The correct answer is D. Identify and evaluate existing practices. When an IS auditor finds no documented security procedures, the correct step is to identify and evaluate whatever informal or undocumented practices may currently exist before drawing conclusions.
Question
During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
Options
- ACreate a procedures document
- BTerminate the audit
- CConduct compliance testing
- DIdentify and evaluate existing practices
How the community answered
(39 responses)- A3% (1)
- B8% (3)
- C10% (4)
- D79% (31)
Why each option
When an IS auditor finds no documented security procedures, the correct step is to identify and evaluate whatever informal or undocumented practices may currently exist before drawing conclusions.
Creating procedures is management's responsibility, not the auditor's - doing so would impair auditor independence.
Terminating the audit is premature because the absence of documented procedures does not mean controls or practices are absent.
Compliance testing cannot be meaningfully performed without first understanding what practices or standards exist to test against.
An auditor's role is to assess the actual state of controls, which includes determining whether compensating or informal practices exist even in the absence of formal documentation. Identifying and evaluating existing practices allows the auditor to form an accurate risk opinion and provide meaningful recommendations rather than assuming a complete absence of controls. This aligns with ISACA auditing standards that require evidence gathering before conclusions are reached.
Concept tested: IS auditor response to missing documented procedures
Source: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-1/the-role-of-the-it-auditor
Topics
Community Discussion
No community discussion yet for this question.