ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 48 - IIA-CIA-Part2 discussion

Report
Export

A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the attempt was not successful. The chief audit executive (CAE) learns of the attack in a casual conversation with an IT auditor. Which of the following actions should the CAE take?

1. Meet with the chief IT officer to discuss the report and control improvements that will be implemented as a result of the security breach, if any.

2. Immediately inform the chair of the audit committee of the security breach, because thus far only the chief IT officer is aware of the incident.

3. Meet with the IT auditor to develop an appropriate audit program to review the organization's Internet-based sales process and key controls.

4. Include the incident in the next quarterly report to the audit committee.

A.
1 and 2
Answers
A.
1 and 2
B.
1 and 3
Answers
B.
1 and 3
C.
2 and 4
Answers
C.
2 and 4
D.
3 and 4
Answers
D.
3 and 4
Suggested answer: B

Explanation:

The chief audit executive (CAE) should meet with the chief IT officer to discuss the incident, the investigation, and any control improvements that will be implemented (1). Additionally, developing an appropriate audit program with the IT auditor to review the organization's Internet-based sales process and key controls (3) is a proactive approach to ensure future incidents are prevented and to enhance the organization's security posture.

Reference: = IIA Standard 2120 - Risk Management and IIA Standard 2201 - Planning Considerations.

asked 18/09/2024
Daria Frutskaya
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first