Information System Auditing Process Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information System Auditing Process flashcards as text
An IS auditor is reviewing a Software Development Life Cycle (SDLC). At which phase should security requirements FIRST be formally incorporated?
Answer: Requirements/design phase
Security requirements should be identified and documented during the requirements and design phase—'security by design'—to avoid costly remediation later.
Which of the following BEST describes the purpose of a follow-up audit?
Answer: To verify that management has implemented agreed-upon corrective actions
A follow-up audit determines whether management has taken timely and effective corrective action to address findings from the original audit.
An IS auditor is evaluating an organization's IT risk management framework. Which outcome BEST demonstrates effective risk management?
Answer: Residual risks are documented and formally accepted by risk owners
Effective risk management acknowledges that not all risk can be eliminated; residual risks should be documented and formally accepted by appropriate risk owners.
When performing a review of physical access controls to a data center, an IS auditor would MOST appropriately:
Answer: Request the access control system logs and compare them against authorized access lists
Reviewing access logs against authorized access lists directly tests whether only authorized individuals accessed the data center and whether any unauthorized access occurred.
Which of the following is the MOST important characteristic of audit evidence?
Answer: It must be sufficient and appropriate to support audit conclusions
Audit standards universally require evidence to be sufficient (adequate quantity) and appropriate (relevant quality and reliability) to support the auditor's conclusions.
An IS auditor discovers that automated system-generated reports used for management decisions cannot be reproduced or reconciled to source data. This is BEST classified as a deficiency in:
Answer: Report integrity and completeness controls
The inability to reproduce or reconcile reports to source data indicates a failure in report integrity controls, undermining confidence in management's decision-making information.
Under ISACA standards, an IS auditor who identifies a significant IT risk outside the original audit scope should:
Answer: Communicate it to management and consider whether scope expansion is warranted
Professional standards require IS auditors to communicate significant risks discovered outside scope to management, and to evaluate whether expanding the scope is appropriate.