CISA · Question #78
During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the
The correct answer is D. Verify whether the licensing agreement allows shared use.. Upon discovering shared license keys, the auditor's best course of action is to verify whether the software licensing agreement permits such usage to determine compliance and identify any potential violation.
Question
During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor's BEST course of action?
Options
- ARecommend the utilization of software licensing monitoring tools.
- BRecommend the purchase of additional software license keys.
- CValidate user need for shared software licenses.
- DVerify whether the licensing agreement allows shared use.
How the community answered
(55 responses)- A22% (12)
- B5% (3)
- C15% (8)
- D58% (32)
Why each option
Upon discovering shared license keys, the auditor's best course of action is to verify whether the software licensing agreement permits such usage to determine compliance and identify any potential violation.
Recommending monitoring tools is a solution-oriented action that should follow the determination of a non-compliance issue, not precede the verification of the license agreement itself.
Recommending the purchase of additional license keys assumes non-compliance, which needs to be verified first according to the existing agreement.
While validating user need for shared licenses might inform future licensing strategies, it does not address the immediate compliance question of whether current sharing is allowed by the existing agreement.
The auditor's primary responsibility is to assess compliance. By verifying the licensing agreement, the auditor establishes whether the observed behavior (shared use) is permissible or a violation, which is crucial before recommending any remedial actions or purchasing additional licenses.
Concept tested: Software licensing compliance audit
Source: https://www.isaca.org/resources/isaca-journal/issues/2009/volume-3/it-audit-and-assurance-standards-glossary-of-terms
Topics
Community Discussion
No community discussion yet for this question.