ExamGecko
Question list
Search
Search

Related questions











Question 349 - CISA discussion

Report
Export

What should an IS auditor do FIRST upon discovering that a service provider did not notify its customers of a security breach?

A.
Notify law enforcement of the finding.
Answers
A.
Notify law enforcement of the finding.
B.
Require the third party to notify customers.
Answers
B.
Require the third party to notify customers.
C.
The audit report with a significant finding.
Answers
C.
The audit report with a significant finding.
D.
Notify audit management of the finding.
Answers
D.
Notify audit management of the finding.
Suggested answer: D

Explanation:

The IS auditor should notify audit management of the finding first, as this is a significant issue that may affect the audit scope and objectives. The IS auditor should not notify law enforcement or require the third party to notify customers without consulting audit management first. The audit report with a significant finding should be issued after the audit is completed and the findings are validated.Reference:ISACA, CISA Review Manual, 27th Edition, 2018, page 247

asked 18/09/2024
Niels de Lange
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first