CISA · Question #247
An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating t
The correct answer is A. Mapping of relevant standards against the organization's controls. Mapping relevant external industry standards directly against the organization's internal controls is most useful for an IS auditor to validate compliance, as it provides a clear, auditable linkage.
Question
An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating the outcome?
Options
- AMapping of relevant standards against the organization's controls
- BInventory of the organization's approved policy exceptions
- CPolicy recommendations from a leading external consulting agency
- DBenchmarking of internal standards against peer organizations
How the community answered
(30 responses)- A83% (25)
- B3% (1)
- C3% (1)
- D10% (3)
Why each option
Mapping relevant external industry standards directly against the organization's internal controls is most useful for an IS auditor to validate compliance, as it provides a clear, auditable linkage.
To validate compliance with external industry standards, an IS auditor needs a clear demonstration that the organization's internal controls directly address and satisfy the requirements of those standards. A mapping document provides this direct linkage, showing exactly which control fulfills which standard requirement, enabling efficient and thorough validation.
An inventory of policy exceptions shows where the organization is *not* compliant or has accepted risks, which is informative but does not directly validate the effectiveness of the overall framework for demonstrating compliance.
Policy recommendations from an external agency are inputs for developing the framework, not direct evidence for validating the *outcome* of compliance with specific standards.
Benchmarking against peer organizations provides context on industry practices but does not directly prove an organization's compliance with *specific* external industry standards; it's a comparative tool, not a compliance validation tool.
Concept tested: IT compliance validation and audit evidence
Source: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/compliance-details
Topics
Community Discussion
No community discussion yet for this question.