nerdexam
IIA

IIA-CIA-PART2 · Question #76

An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor…

The correct answer is D. The incidents of noncompliance exceed the tolerance level and should be included in the final. When an internal auditor finds that the incidents of noncompliance exceed the organization's acceptable tolerance level, this should be included in the final engagement report. In this case, the 8 out of 90 desks found with sensitive information represent an 8.9% noncompliance…

Communicating Engagement Results and Monitoring Progress

Question

An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?

Options

  • AThe matter does not need to be reported, because the noncompliant findings fall within the
  • BThe deviations are within the acceptable tolerance limit, so the matter only needs to be reported to
  • CThe incidents of noncompliance fall outside the acceptable tolerance limit and require immediate
  • DThe incidents of noncompliance exceed the tolerance level and should be included in the final

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    9% (4)
  • C
    2% (1)
  • D
    85% (39)

Explanation

When an internal auditor finds that the incidents of noncompliance exceed the organization's acceptable tolerance level, this should be included in the final engagement report. In this case, the 8 out of 90 desks found with sensitive information represent an 8.9% noncompliance rate, which exceeds the organization's tolerance limit of 4%. Reporting this observation in the final engagement report ensures that management is informed and can take necessary corrective actions to address the noncompliance.

Topics

#noncompliance#tolerance limits#information security policy#audit reporting

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice