List of questions
Related questions
Question 635 - CISA discussion
During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor's BEST course of action?
A.
Report the deviation by the control owner in the audit report.
B.
Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.
C.
Cancel the follow-up audit and reschedule for the next audit period.
D.
Request justification from management for not implementing the recommended control.
Your answer:
0 comments
Sorted by
Leave a comment first