nerdexam
Isaca

CISA · Question #153

Which of the following is MOST useful to an IS auditor performing a review of access controls for a document management system?

The correct answer is D. A system-generated list of staff and their project assignments, roles, and responsibilities. For reviewing access controls, an IS auditor needs detailed, current, and objective information about who has what access within the system.

Submitted by yaw92· Apr 18, 2026Protection of Information Assets

Question

Which of the following is MOST useful to an IS auditor performing a review of access controls for a document management system?

Options

  • AInformation provided by the audit team lead on the authentication systems used by the
  • BPolicies and procedures for managing documents provided by department heads
  • CPrevious audit reports related to other departments' use of the same system
  • DA system-generated list of staff and their project assignments, roles, and responsibilities

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    11% (6)
  • C
    6% (3)
  • D
    81% (44)

Why each option

For reviewing access controls, an IS auditor needs detailed, current, and objective information about who has what access within the system.

AInformation provided by the audit team lead on the authentication systems used by the

Information from the audit team lead is secondary to direct evidence and might not be specific enough for a detailed access control review.

BPolicies and procedures for managing documents provided by department heads

Policies and procedures describe how access should be managed but do not confirm actual access rights or their enforcement within the system.

CPrevious audit reports related to other departments' use of the same system

Previous audit reports from other departments might offer context but are not directly relevant to the current state of access controls for the specific system and department under review.

DA system-generated list of staff and their project assignments, roles, and responsibilitiesCorrect

A system-generated list of staff, their project assignments, roles, and responsibilities provides granular, auditable evidence of actual access rights and assignments within the document management system, which is critical for verifying that access aligns with the principle of least privilege and job duties. This list can be directly compared against access matrixes and organizational structures to identify discrepancies or unauthorized access.

Concept tested: IS audit evidence for access controls

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-and-compliance

Topics

#Access controls#Audit evidence#Logical access#Document management system

Community Discussion

No community discussion yet for this question.

Full CISA Practice