IIA-CIA-PART2 · Question #449
The internal audit activity needs to review the information security function but does not have the IT expertise needed for the engagement. Which of the following actions should the chief audit…
The correct answer is C. Contract an external service provider auditor with the experience necessary to perform the audit. When the internal audit activity lacks the necessary IT expertise to review the information security function, the chief audit executive (CAE) should contract an external service provider with the required experience. This ensures that the audit is conducted effectively and in…
Question
The internal audit activity needs to review the information security function but does not have the IT expertise needed for the engagement. Which of the following actions should the chief audit executive take to ensure the internal audit activity conforms with the Standards?
Options
- AAssign the engagement to a staff auditor and closely review his work and report.
- BAssign the engagement to a senior auditor, who carefully researches and studies the company's IT
- CContract an external service provider auditor with the experience necessary to perform the audit.
- DPerform the audit herself and work closely with the information security function to obtain expertise
How the community answered
(30 responses)- A7% (2)
- B10% (3)
- C80% (24)
- D3% (1)
Explanation
When the internal audit activity lacks the necessary IT expertise to review the information security function, the chief audit executive (CAE) should contract an external service provider with the required experience. This ensures that the audit is conducted effectively and in accordance with the Standards, which require internal auditors to have or acquire the necessary skills to perform
Topics
Community Discussion
No community discussion yet for this question.