nerdexam
Isaca

CISA · Question #474

An IS auditor discovers there are no documented security procedures. What should be the NEXT step?

The correct answer is A. Identify and evaluate the current security practices implemented by the organization.. When no documented security procedures exist, the IS auditor’s next step is to identify and assess the security practices currently in place. This allows the auditor to determine whether effective controls are operating, even if undocumented, and to evaluate the associated risks

Submitted by takeshi77· Apr 18, 2026Information System Auditing Process

Question

An IS auditor discovers there are no documented security procedures. What should be the NEXT step?

Options

  • AIdentify and evaluate the current security practices implemented by the organization.
  • BIdentify compensating controls for the lack of documentation.
  • CAssist information security management with preparing security procedures.
  • DReview security incident logs and related metrics.

How the community answered

(62 responses)
  • A
    79% (49)
  • B
    5% (3)
  • C
    13% (8)
  • D
    3% (2)

Explanation

When no documented security procedures exist, the IS auditor’s next step is to identify and assess the security practices currently in place. This allows the auditor to determine whether effective controls are operating, even if undocumented, and to evaluate the associated risks before recommending formal documentation.

Topics

#Audit methodology#Security documentation#Control evaluation#Audit findings

Community Discussion

No community discussion yet for this question.

Full CISA Practice