ExamGecko
Question list
Search
Search

Related questions











Question 309 - CISA discussion

Report
Export

Which of the following must be in place before an IS auditor initiates audit follow-up activities?

A.
Available resources for the activities included in the action plan
Answers
A.
Available resources for the activities included in the action plan
B.
A management response in the final report with a committed implementation date
Answers
B.
A management response in the final report with a committed implementation date
C.
A heal map with the gaps and recommendations displayed in terms of risk
Answers
C.
A heal map with the gaps and recommendations displayed in terms of risk
D.
Supporting evidence for the gaps and recommendations mentioned in the audit report
Answers
D.
Supporting evidence for the gaps and recommendations mentioned in the audit report
Suggested answer: B

Explanation:

This must be in place before an IS auditor initiates audit follow-up activities, because it indicates that management has acknowledged and accepted the audit findings and recommendations, and has agreed to take corrective actions within a specified timeframe. Audit follow-up activities are the processes and procedures that the IS auditor performs to verify that management has implemented the agreed-upon actions effectively and in a timely manner, and that the audit findings have been resolved or mitigated.

The other options are not required to be in place before an IS auditor initiates audit follow-up activities:

Available resources for the activities included in the action plan. This is a factor that may affect the feasibility and success of the action plan, but it is not a prerequisite for the audit follow-up activities. The IS auditor should assess the availability and adequacy of the resources for the action plan during the audit planning and execution phases, and provide recommendations accordingly. However, the IS auditor does not need to wait for the resources to be available before initiating the audit follow-up activities.

A heat map with the gaps and recommendations displayed in terms of risk. This is a tool that may help the IS auditor prioritize and communicate the gaps and recommendations, but it is not a requirement for the audit follow-up activities. A heat map is a graphical representation of data that uses colors to indicate the level of risk or impact of each gap or recommendation. The IS auditor may use a heat map to support the audit report or presentation, but it does not replace the need for a management response with a committed implementation date.

Supporting evidence for the gaps and recommendations mentioned in the audit report. This is a component that should be included in the audit report, but it is not a condition for the audit follow-up activities. Supporting evidence is the information or data that supports or substantiates the audit findings and recommendations. The IS auditor should collect and document sufficient, reliable, relevant, and useful evidence during the audit execution phase, and present it in the audit report. However, the IS auditor does not need to have supporting evidence in place before initiating the audit follow-up activities.

asked 18/09/2024
Robert Petty
52 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first