SSCP Security Auditing & Compliance Standards 5 — Questions and Answers
Question 1: Which control framework specifically addresses security requirements for US federal information systems and is mandated by law?
- ISO 27001
- SOC 2
- FISMA / NIST SP 800-53 (Correct answer)
- PCI DSS
Correct answer: FISMA / NIST SP 800-53
FISMA (Federal Information Security Modernization Act) mandates that federal agencies implement security controls defined in NIST SP 800-53.
Question 2: An organization receives an audit finding that its change management process lacks formal rollback procedures. This finding is BEST addressed by:
- Accepting the risk and documenting a risk acceptance form
- Updating change management policy and procedures to include rollback steps and testing (Correct answer)
- Transferring the risk to a managed service provider
- Implementing a web application firewall
Correct answer: Updating change management policy and procedures to include rollback steps and testing
The finding identifies a process gap; the correct remediation is to update procedures to include rollback planning and test those procedures.
Question 3: Which term describes the process where an organization independently verifies that its own controls are operating as intended before an external audit?
- External audit
- Third-party assessment
- Internal audit / self-assessment (Correct answer)
- Penetration test
Correct answer: Internal audit / self-assessment
Internal audits or self-assessments allow organizations to proactively identify gaps and remediate them before external auditors review the same controls.
Question 4: Under SOX Section 404, management and external auditors must report on the effectiveness of:
- Physical security controls
- Internal controls over financial reporting (Correct answer)
- Software development lifecycle processes
- Network perimeter defenses
Correct answer: Internal controls over financial reporting
SOX Section 404 requires management to assess and report on internal controls over financial reporting (ICFR), with external auditor attestation.
Question 5: Which evidence collection method is considered MOST reliable in an audit because it is obtained directly by the auditor without intermediary involvement?
- Testimonial evidence from management
- Documentary evidence provided by the auditee
- Analytical evidence from trend analysis
- Direct observation by the auditor (Correct answer)
Correct answer: Direct observation by the auditor
Direct observation is the most reliable audit evidence because the auditor personally witnesses the control in operation, eliminating reliance on auditee-supplied information.
Question 6: A company operating in the EU and US must align its data transfer practices with which mechanism that governs cross-border personal data transfers post-Privacy Shield?
- Safe Harbor Framework
- EU-US Data Privacy Framework (Correct answer)
- COPPA
- CCPA
Correct answer: EU-US Data Privacy Framework
The EU-US Data Privacy Framework (2023) replaced Privacy Shield and provides the legal mechanism for transatlantic personal data transfers under GDPR.
Question 7: During an audit, the auditor reviews system-generated reports rather than paper records. This approach is called:
- Computer-assisted audit techniques (CAATs) (Correct answer)
- Manual walkthrough testing
- Inquiry and observation
- Substantive testing
Correct answer: Computer-assisted audit techniques (CAATs)
Computer-Assisted Audit Techniques (CAATs) use software tools to analyze large volumes of electronic data, improving audit efficiency and coverage.
Which control framework specifically addresses security requirements for US federal information systems and is mandated by law?