nerdexam
Isaca

CCAK · Question #121

While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate…

The correct answer is C. Documenting the finding in the audit report and sharing the gap with the relevant stakeholders. An auditor's role is to identify, document, and communicate findings - not to remediate them. Directly asking the cloud administrator to fix the issue (B) would mean the auditor steps outside their role and takes on management responsibility, which compromises independence…

Cloud Audit Reporting and Assurance

Question

While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate action for the auditor to perform?

Options

  • AHighlighting the gap to the audit sponsor at the sponsor's earliest possible availability
  • BAsking the organization's cloud administrator to immediately close the gap by updating the
  • CDocumenting the finding in the audit report and sharing the gap with the relevant stakeholders
  • DInforming the organization's internal audit manager immediately about the gap

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    84% (31)
  • D
    3% (1)

Explanation

An auditor's role is to identify, document, and communicate findings - not to remediate them. Directly asking the cloud administrator to fix the issue (B) would mean the auditor steps outside their role and takes on management responsibility, which compromises independence. Notifying only the internal audit manager (D) is too narrow and may not reach the data/privacy owners who need to act. Waiting for the audit sponsor's 'earliest availability' (A) is inappropriate for a critical exposure of PII - urgency is required. The correct course is to document the finding formally in the audit report AND immediately share it with the relevant stakeholders (data owners, security team, compliance officers) so that remediation can begin without the auditor taking ownership of the fix.

Topics

#Audit findings#Reporting procedures#Auditor responsibilities#Stakeholder communication

Community Discussion

No community discussion yet for this question.

Full CCAK Practice