CAS-002 · Question #5
The internal auditor at Company ABC has completed the annual audit of the company's financial system. The audit report indicates that the accounts receivable department has not followed proper…
The correct answer is C. Implement mandatory training E. Review company procedures. When auditors identify a procedural compliance failure, the ISO should address both the root cause through training and the process gap by reviewing procedures.
Question
The internal auditor at Company ABC has completed the annual audit of the company's financial system. The audit report indicates that the accounts receivable department has not followed proper record disposal procedures during a COOP/BCP tabletop exercise involving manual processing of financial transactions. Which of the following should be the Information Security Officer's (ISO's) recommendation? (Select TWO).
Options
- AWait for the external audit results
- BPerform another COOP exercise
- CImplement mandatory training
- DDestroy the financial transactions
- EReview company procedures
How the community answered
(26 responses)- A4% (1)
- B12% (3)
- C77% (20)
- D8% (2)
Why each option
When auditors identify a procedural compliance failure, the ISO should address both the root cause through training and the process gap by reviewing procedures.
Waiting for an external audit is a passive response that delays corrective action and leaves the compliance gap unresolved in the interim.
Performing another COOP exercise without first correcting the training and procedural deficiencies would likely reproduce the same compliance failures.
Mandatory training directly addresses the finding that staff did not follow proper record disposal procedures, ensuring employees understand their obligations and the correct steps to take during manual processing scenarios.
Destroying financial transactions could constitute improper destruction of records and potentially obstruct audit trails or legal obligations.
Reviewing company procedures ensures that the documented processes are clear, current, and aligned with regulatory and policy requirements, closing any ambiguity that may have contributed to the non-compliance observed during the exercise.
Concept tested: Incident response to audit findings - training and procedure review
Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.