ExamGecko
Question list
Search
Search

Related questions

Question 97 - CISA discussion

Report
Export

Which of the following should be an IS auditor's PRIMARY focus when developing a risk-based IS audit program?

A.
Portfolio management
Answers
A.
Portfolio management
B.
Business plans
Answers
B.
Business plans
C.
Business processes
Answers
C.
Business processes
D.
IT strategic plans
Answers
D.
IT strategic plans
Suggested answer: C

Explanation:

Business processes should be the primary focus of an IS auditor when developing a risk-based IS audit program, because they represent the core activities and functions of the organization that support its objectives and goals. Business processes also involve the use of IT resources and systems that may pose risks to the organization's performance and compliance. A risk-based IS audit program should identify and assess the risks associated with the business processes and determine the appropriate audit scope and procedures to provide assurance on their effectiveness and efficiency.Portfolio management, business plans, and IT strategic plans are also relevant factors for developing a risk-based IS audit program, but they are not as important as business processes.Reference:CISA Review Manual (Digital Version), Chapter 2, Section 2.2.1

asked 18/09/2024
Mustafa Hussien
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first