CISA · Question #475
When conducting a follow-up of previous audit findings, an IS auditor is told by management that a recommendation to make security changes to an application has not been implemented. The IS auditor sh
The correct answer is C. the associated risk is still relevant.. Before taking any further action, the IS auditor should first determine whether the risk linked to the unimplemented recommendation still exists. If the risk is no longer relevant due to changes in the environment or controls, follow-up actions may not be necessary. If it remains
Question
When conducting a follow-up of previous audit findings, an IS auditor is told by management that a recommendation to make security changes to an application has not been implemented. The IS auditor should FIRST determine whether:
Options
- Athe issue should be escalated.
- Bthe recommendation should be reissued.
- Cthe associated risk is still relevant.
- Dadditional time to implement changes is needed.
How the community answered
(30 responses)- A7% (2)
- B3% (1)
- C80% (24)
- D10% (3)
Explanation
Before taking any further action, the IS auditor should first determine whether the risk linked to the unimplemented recommendation still exists. If the risk is no longer relevant due to changes in the environment or controls, follow-up actions may not be necessary. If it remains relevant, further escalation or reissuance can then be considered.
Topics
Community Discussion
No community discussion yet for this question.