CISA · Question #546
An IS auditor learns that individual teams are allowed to implement and manage their use of robotic process automation (RPA). Which of the following controls would BEST enable the IT department to…
The correct answer is A. Uses of RPA are periodically evaluated to ensure they are functioning as intended. Periodically evaluating RPA uses to ensure they function as intended is the best governance control because it provides ongoing operational oversight of all decentralized RPA implementations, ensuring they continue to operate correctly over time. Option B (admin access to the…
Question
An IS auditor learns that individual teams are allowed to implement and manage their use of robotic process automation (RPA). Which of the following controls would BEST enable the IT department to effectively govern the use of end-user computing (EUC) in this situation?
Options
- AUses of RPA are periodically evaluated to ensure they are functioning as intended.
- BIT has administrative access to the RPA management console.
- CIT has access to view and manage all secrets stored within the RPA tool.
- DUses of RPA are inventoried and assessed retroactively based on risk.
How the community answered
(59 responses)- A46% (27)
- B17% (10)
- C29% (17)
- D8% (5)
Explanation
Periodically evaluating RPA uses to ensure they function as intended is the best governance control because it provides ongoing operational oversight of all decentralized RPA implementations, ensuring they continue to operate correctly over time. Option B (admin access to the RPA console) is an access control, not a governance mechanism. Option C (access to secrets) is a security control but does not address broader governance. Option D describes retroactive, reactive assessment, which is weaker than proactive, periodic evaluation and may leave risks undetected for extended periods.
Topics
Community Discussion
No community discussion yet for this question.