nerdexam
Isaca

CISA · Question #27

Which of the following is MOST important for an IS auditor to assess during a post- implementation review of a newly modified IT application developed in-house?

The correct answer is B. Sufficiency of implemented controls. During a post-implementation review, the most critical aspect for an IS auditor to assess is the sufficiency of the implemented controls to ensure the application meets security, integrity, and availability objectives.

Submitted by kev92· Apr 18, 2026Information Systems Acquisition, Development and Implementation

Question

Which of the following is MOST important for an IS auditor to assess during a post- implementation review of a newly modified IT application developed in-house?

Options

  • ARollback plans for changes
  • BSufficiency of implemented controls
  • CUpdates required for end user manuals
  • DResource management plan

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    76% (32)
  • C
    2% (1)
  • D
    14% (6)

Why each option

During a post-implementation review, the most critical aspect for an IS auditor to assess is the sufficiency of the implemented controls to ensure the application meets security, integrity, and availability objectives.

ARollback plans for changes

Rollback plans are important during the implementation phase and for disaster recovery, but assessing their existence is not the most important part of a post-implementation *control* review, which focuses on the deployed system.

BSufficiency of implemented controlsCorrect

The primary role of an IS auditor is to evaluate the effectiveness of controls. In a post-implementation review, assessing the sufficiency of implemented controls ensures that the newly modified application functions securely, accurately, and reliably, mitigating identified risks and meeting regulatory requirements and business objectives. This includes evaluating access controls, input/output controls, processing controls, and audit trails.

CUpdates required for end user manuals

Updates to end-user manuals are part of change management and user adoption, which are important, but not the core *control* assessment an IS auditor performs on the application itself.

DResource management plan

A resource management plan is relevant during project planning and execution, not the primary focus of a post-implementation review of the operational effectiveness of IT application controls.

Concept tested: Post-implementation audit focus

Source: https://www.isaca.org/resources/isaca-journal/2012/volume-4/a-framework-for-it-post-implementation-reviews

Topics

#Post-implementation review#IT controls#Application controls#IS audit objectives

Community Discussion

No community discussion yet for this question.

Full CISA Practice