ExamGecko
Question list
Search
Search

Related questions

Question 146 - CISA discussion

Report
Export

Which of the following should be an IS auditor's GREATEST consideration when scheduling follow-up activities for agreed-upon management responses to remediate audit observations?

A.
Business interruption due to remediation
Answers
A.
Business interruption due to remediation
B.
IT budgeting constraints
Answers
B.
IT budgeting constraints
C.
Availability of responsible IT personnel
Answers
C.
Availability of responsible IT personnel
D.
Risk rating of original findings
Answers
D.
Risk rating of original findings
Suggested answer: D

Explanation:

The most important consideration for an IS auditor when scheduling follow-up activities for agreed-upon management responses to remediate audit observations is the risk rating of original findings. The risk rating of original findings is an assessment of the potential impact or likelihood of an audit issue or observation on the organization's objectives, operations, or reputation. The risk rating of original findings can help determine the priority and urgency of follow-up activities for agreed-upon management responses to remediate audit observations by ensuring that high-risk issues are addressed first and more frequently than low-risk issues. The other options are not as important as the risk rating of original findings in scheduling follow-up activities for agreed-upon management responses to remediate audit observations, as they do not reflect the significance or severity of audit issues or observations. Business interruption due to remediation is a possible consequence of implementing corrective actions to address audit issues or observations, but it does not indicate the priority or urgency of follow-up activities. IT budgeting constraints is a possible factor that may affect the availability or feasibility of resources for implementing corrective actions to address audit issues or observations, but it does not indicate the priority or urgency of follow-up activities. Availability of responsible IT personnel is a possible factor that may affect the accountability or responsiveness of staff for implementing corrective actions to address audit issues or observations, but it does not indicate the priority or urgency of follow-up activities.Reference:CISA Review Manual (Digital Version), Chapter 2, Section 2.4

asked 18/09/2024
Fai Malali
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first