ExamGecko
Question list
Search
Search

Related questions

Question 17 - CISA discussion

Report
Export

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor's BEST course of action?

A.
Require the auditee to address the recommendations in full.
Answers
A.
Require the auditee to address the recommendations in full.
B.
Adjust the annual risk assessment accordingly.
Answers
B.
Adjust the annual risk assessment accordingly.
C.
Evaluate senior management's acceptance of the risk.
Answers
C.
Evaluate senior management's acceptance of the risk.
D.
Update the audit program based on management's acceptance of risk.
Answers
D.
Update the audit program based on management's acceptance of risk.
Suggested answer: C

Explanation:

The best course of action for an IS auditor who finds that some critical recommendations have not been implemented is to evaluate senior management's acceptance of the risk. The IS auditor should understand the reasons why the recommendations have not been implemented and the implications for the organization's risk exposure. The IS auditor should also verify that senior management has formally acknowledged and accepted the residual risk and has documented the rationale and justification for their decision. The IS auditor should communicate the findings and the risk acceptance to the audit committee and other relevant stakeholders.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Solanki Narendra
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first