nerdexam
EC-Council

712-50 · Question #120

A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should…

The correct answer is C. Review the recommendations and follow up to see if audit implemented the changes. Option C is correct because the CISO's first priority must be to understand the current state relative to what was already identified. Reviewing recommendations and verifying whether prior audit findings were remediated tells the CISO what gaps still exist, what risks are…

IS Management Controls and Auditing Management

Question

A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be the CISO's FIRST priority?

Options

  • AHave internal audit conduct another audit to see what has changed.
  • BContract with an external audit company to conduct an unbiased audit
  • CReview the recommendations and follow up to see if audit implemented the changes
  • DMeet with audit team to determine a timeline for corrections

How the community answered

(66 responses)
  • A
    11% (7)
  • B
    6% (4)
  • C
    80% (53)
  • D
    3% (2)

Explanation

Option C is correct because the CISO's first priority must be to understand the current state relative to what was already identified. Reviewing recommendations and verifying whether prior audit findings were remediated tells the CISO what gaps still exist, what risks are already known, and whether the organization has a track record of addressing issues - all critical before commissioning new work or setting timelines.

Why the distractors are wrong:

  • A (internal audit): Ordering a brand-new audit before understanding what came from the last one wastes resources and skips the accountability check - you'd be flying blind about known issues.
  • B (external audit): Same problem as A, and it's premature and costly before the CISO has even assessed what was already found; external audits are valuable but not the first step.
  • D (meet with audit team on timelines): Setting correction timelines only makes sense after you know which recommendations were already implemented and which weren't - otherwise you're scheduling work on potentially solved problems.

Memory tip: Think of it as the "look before you leap" rule. A new CISO walks in with a report already in hand - read and verify that first before spending budget or time on anything new. In security management, always assess the existing baseline before acting: Review → Verify → Then plan next steps.

Topics

#audit follow-up#audit recommendations#compliance management#CISO responsibilities

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice