CISA · Question #93
Which of the following would be MOST important to include in an IS audit report?
The correct answer is D. The level of unmitigated risk along with business impact. The most important information in an IS audit report is the level of unmitigated risk and its business impact, as this informs management about critical exposures requiring attention.
Question
Which of the following would be MOST important to include in an IS audit report?
Options
- AObservations not reported as findings due to inadequate evidence
- BThe roadmap for addressing the various risk areas
- CSpecific technology solutions for each audit observation
- DThe level of unmitigated risk along with business impact
How the community answered
(62 responses)- A6% (4)
- B10% (6)
- C3% (2)
- D81% (50)
Why each option
The most important information in an IS audit report is the level of unmitigated risk and its business impact, as this informs management about critical exposures requiring attention.
Observations with inadequate evidence are typically excluded from formal findings to maintain the credibility and objectivity of the audit report.
A roadmap for addressing risk areas is typically developed by management in response to audit findings, rather than being a primary component of the audit report itself.
While an audit may suggest general control improvements, specific technology solutions are usually the responsibility of management or IT teams to implement, not the auditor to prescribe in detail.
An IS audit's primary purpose is to identify risks and evaluate controls. By reporting the level of unmitigated risk along with its business impact, the audit report provides management with clear, actionable information about the most significant exposures, enabling informed decision-making regarding remediation priorities.
Concept tested: Essential elements of an IS audit report
Topics
Community Discussion
No community discussion yet for this question.