QuestionQ102

Information System Auditing Process

During an identity and access management audit, an IS auditor discovers that the engagement audit plan excludes testing of controls governing third-party access. What would be the auditor's BEST course of action?

Explanation

Audit scope and control testing should be based on the documented risk assessment and planning rationale. Determining whether third-party access risk was identified in the planning documents establishes whether the omitted testing reflects an unaddressed risk or an intentional, risk-based scope decision.

Community Discussion

No comments yet. Be the first to start the discussion!