nerdexam
Isaca

CISA · Question #475

When conducting a follow-up of previous audit findings, an IS auditor is told by management that a recommendation to make security changes to an application has not been implemented. The IS auditor sh

The correct answer is C. the associated risk is still relevant.. Before taking any further action, the IS auditor should first determine whether the risk linked to the unimplemented recommendation still exists. If the risk is no longer relevant due to changes in the environment or controls, follow-up actions may not be necessary. If it remains

Submitted by ngozi_ng· Apr 18, 2026Information System Auditing Process

Question

When conducting a follow-up of previous audit findings, an IS auditor is told by management that a recommendation to make security changes to an application has not been implemented. The IS auditor should FIRST determine whether:

Options

  • Athe issue should be escalated.
  • Bthe recommendation should be reissued.
  • Cthe associated risk is still relevant.
  • Dadditional time to implement changes is needed.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    80% (24)
  • D
    10% (3)

Explanation

Before taking any further action, the IS auditor should first determine whether the risk linked to the unimplemented recommendation still exists. If the risk is no longer relevant due to changes in the environment or controls, follow-up actions may not be necessary. If it remains relevant, further escalation or reissuance can then be considered.

Topics

#Audit follow-up#Risk assessment#Audit recommendations#IS audit process

Community Discussion

No community discussion yet for this question.

Full CISA Practice