nerdexam
Isaca

CISA · Question #453

Which of the following is the PRIMARY function of an internal IS auditor when the organization acquires a new IT system to support its business strategy?

The correct answer is D. Evaluating IT risk and controls. The internal IS auditor’s foremost responsibility during a system acquisition is to assess whether IT risks are identified and that appropriate control measures are in place to manage those risks. This evaluation ensures the new system supports the business strategy within a cont

Submitted by andres_qro· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

Which of the following is the PRIMARY function of an internal IS auditor when the organization acquires a new IT system to support its business strategy?

Options

  • AIdentifying significant IT errors and fraud
  • BAssessing system development life cycle (SDLC) controls
  • CImplementing risk and control gap mitigation
  • DEvaluating IT risk and controls

How the community answered

(21 responses)
  • A
    5% (1)
  • D
    95% (20)

Explanation

The internal IS auditor’s foremost responsibility during a system acquisition is to assess whether IT risks are identified and that appropriate control measures are in place to manage those risks. This evaluation ensures the new system supports the business strategy within a controlled risk

Topics

#IS Auditor Role#System Acquisition#IT Risk Management#Control Assessment

Community Discussion

No community discussion yet for this question.

Full CISA Practice