CISA · Question #474
An IS auditor discovers there are no documented security procedures. What should be the NEXT step?
The correct answer is A. Identify and evaluate the current security practices implemented by the organization.. When no documented security procedures exist, the IS auditor’s next step is to identify and assess the security practices currently in place. This allows the auditor to determine whether effective controls are operating, even if undocumented, and to evaluate the associated risks
Question
An IS auditor discovers there are no documented security procedures. What should be the NEXT step?
Options
- AIdentify and evaluate the current security practices implemented by the organization.
- BIdentify compensating controls for the lack of documentation.
- CAssist information security management with preparing security procedures.
- DReview security incident logs and related metrics.
How the community answered
(62 responses)- A79% (49)
- B5% (3)
- C13% (8)
- D3% (2)
Explanation
When no documented security procedures exist, the IS auditor’s next step is to identify and assess the security practices currently in place. This allows the auditor to determine whether effective controls are operating, even if undocumented, and to evaluate the associated risks before recommending formal documentation.
Topics
Community Discussion
No community discussion yet for this question.