ExamGecko
Question list
Search
Search

Related questions











Question 292 - CISA discussion

Report
Export

Which of the following MUST be completed as part of the annual audit planning process?

A.
Business impact analysis (BIA)
Answers
A.
Business impact analysis (BIA)
B.
Fieldwork
Answers
B.
Fieldwork
C.
Risk assessment
Answers
C.
Risk assessment
D.
Risk control matrix
Answers
D.
Risk control matrix
Suggested answer: C

Explanation:

Risk assessment is a mandatory part of the annual audit planning process, as it helps to identify and prioritize the areas that pose the highest risk to the organization's objectives and operations. Risk assessment involves analyzing the internal and external factors that affect the organization's risk profile, evaluating the likelihood and impact of potential events or scenarios, assessing the existing controls and mitigation strategies, and determining the residual risk level. Based on the risk assessment results, the IS auditor can allocate resources and schedule audits accordingly. A business impact analysis (BIA) is a process that identifies and evaluates the critical business functions and processes that could be disrupted by a disaster or incident, and estimates the potential impact on the organization's operations, reputation and finances. A BIA is not a mandatory part of the annual audit planning process, but it can be used as an input for risk assessment or as a subject for audit. Fieldwork is the phase of an audit where the IS auditor collects evidence to support the audit objectives and conclusions. Fieldwork is not part of the annual audit planning process, but it is part of each individual audit engagement. A risk control matrix is a tool that maps the risks identified in a risk assessment to the controls that mitigate them.A risk control matrix is not a mandatory part of the annual audit planning process, but it can be used as an output of risk assessment or as a tool for audit testing.Reference:CISA Review Manual (Digital Version)1, Chapter 1: Information Systems Auditing Process, Section 1.2: Audit Planning.

asked 18/09/2024
Ezrah James panuelos
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first