QuestionQ133

Information System Auditing Process

During a follow-up audit, an IS auditor discovers that senior management has put in place a remediation action plan different from the one previously agreed. Which of the following is the auditor's BEST course of action?

Explanation

An alternative remediation action can be acceptable if the implemented control adequately mitigates the underlying risk. The auditor should evaluate the control to determine whether it reduces the risk to an acceptable level, rather than focusing solely on whether management adopted the originally recommended control.

Community Discussion

No comments yet. Be the first to start the discussion!