CISA · Question #153
Which of the following is MOST useful to an IS auditor performing a review of access controls for a document management system?
The correct answer is D. A system-generated list of staff and their project assignments, roles, and responsibilities. For reviewing access controls, an IS auditor needs detailed, current, and objective information about who has what access within the system.
Question
Which of the following is MOST useful to an IS auditor performing a review of access controls for a document management system?
Options
- AInformation provided by the audit team lead on the authentication systems used by the
- BPolicies and procedures for managing documents provided by department heads
- CPrevious audit reports related to other departments' use of the same system
- DA system-generated list of staff and their project assignments, roles, and responsibilities
How the community answered
(54 responses)- A2% (1)
- B11% (6)
- C6% (3)
- D81% (44)
Why each option
For reviewing access controls, an IS auditor needs detailed, current, and objective information about who has what access within the system.
Information from the audit team lead is secondary to direct evidence and might not be specific enough for a detailed access control review.
Policies and procedures describe how access should be managed but do not confirm actual access rights or their enforcement within the system.
Previous audit reports from other departments might offer context but are not directly relevant to the current state of access controls for the specific system and department under review.
A system-generated list of staff, their project assignments, roles, and responsibilities provides granular, auditable evidence of actual access rights and assignments within the document management system, which is critical for verifying that access aligns with the principle of least privilege and job duties. This list can be directly compared against access matrixes and organizational structures to identify discrepancies or unauthorized access.
Concept tested: IS audit evidence for access controls
Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-and-compliance
Topics
Community Discussion
No community discussion yet for this question.