nerdexam
Isaca

CISA · Question #247

An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating t

The correct answer is A. Mapping of relevant standards against the organization's controls. Mapping relevant external industry standards directly against the organization's internal controls is most useful for an IS auditor to validate compliance, as it provides a clear, auditable linkage.

Submitted by rania.sa· Apr 18, 2026Information System Auditing Process

Question

An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating the outcome?

Options

  • AMapping of relevant standards against the organization's controls
  • BInventory of the organization's approved policy exceptions
  • CPolicy recommendations from a leading external consulting agency
  • DBenchmarking of internal standards against peer organizations

How the community answered

(30 responses)
  • A
    83% (25)
  • B
    3% (1)
  • C
    3% (1)
  • D
    10% (3)

Why each option

Mapping relevant external industry standards directly against the organization's internal controls is most useful for an IS auditor to validate compliance, as it provides a clear, auditable linkage.

AMapping of relevant standards against the organization's controlsCorrect

To validate compliance with external industry standards, an IS auditor needs a clear demonstration that the organization's internal controls directly address and satisfy the requirements of those standards. A mapping document provides this direct linkage, showing exactly which control fulfills which standard requirement, enabling efficient and thorough validation.

BInventory of the organization's approved policy exceptions

An inventory of policy exceptions shows where the organization is *not* compliant or has accepted risks, which is informative but does not directly validate the effectiveness of the overall framework for demonstrating compliance.

CPolicy recommendations from a leading external consulting agency

Policy recommendations from an external agency are inputs for developing the framework, not direct evidence for validating the *outcome* of compliance with specific standards.

DBenchmarking of internal standards against peer organizations

Benchmarking against peer organizations provides context on industry practices but does not directly prove an organization's compliance with *specific* external industry standards; it's a comparative tool, not a compliance validation tool.

Concept tested: IT compliance validation and audit evidence

Source: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/compliance-details

Topics

#Compliance#Audit Evidence#Control Mapping#Policy Framework

Community Discussion

No community discussion yet for this question.

Full CISA Practice