QuestionQ28

Information System Auditing Process

An IS auditor is scheduled to perform a follow-up and is informed by operational management that new priorities stopped them from implementing the action plan. Management intends to address the audit issues after the next quarter. What should be the auditor's NEXT course of action?

Explanation

Delaying an agreed corrective action can leave the underlying control weakness and its associated exposure in place. The auditor should assess the risk resulting from the deferred implementation to determine the significance of the continued exposure and whether further reporting or escalation is warranted. ISACA guidance on follow-up activities requires monitoring whether management has planned and taken appropriate, timely action on findings and recommendations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!