ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 88 - IIA-CIA-Part2 discussion

Report
Export

An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?

A.
The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
Answers
A.
The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
B.
The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
Answers
B.
The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
C.
The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
Answers
C.
The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
D.
The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
Answers
D.
The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
Suggested answer: D

Explanation:

When an internal auditor finds that the incidents of noncompliance exceed the organization's acceptable tolerance level, this should be included in the final engagement report. In this case, the 8 out of 90 desks found with sensitive information represent an 8.9% noncompliance rate, which exceeds the organization's tolerance limit of 4%. Reporting this observation in the final engagement report ensures that management is informed and can take necessary corrective actions to address the noncompliance.

IIA Standards: 2410 - Criteria for Communicating

IIA Practice Guide: Reporting and Monitoring

asked 18/09/2024
fabio josca
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first