ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium
An IS auditor is reviewing an organization's user access management process. The audit program includes steps to verify that user access reviews are performed quarterly by managers. Which of the following is the BEST audit procedure to gather evidence that these reviews are actually occurring and are effective?
- AInterviewing IT personnel responsible for system administration.
- BInspecting signed user access review reports and sampling changes made.
- CReviewing system-generated logs of access changes.
- DObserving a manager performing a user access review.
Show answer & explanationAnswer & explanation
Correct answer: B. Inspecting signed user access review reports and sampling changes made.
Inspecting signed review reports provides direct evidence of the reviews being performed and documented. Sampling changes made during these reviews (e.g., access removed) provides evidence of their effectiveness.
Why the other options are wrong
- A. Interviews provide verbal evidence, which is less reliable than documentary evidence.
- C. System logs show changes, but not necessarily that they resulted from a manager's quarterly review or that the review itself was effective.
- D. Observation is a snapshot in time and doesn't confirm consistent, effective quarterly reviews over the audit period.
Audit Procedure - Evidence Gathering
Audit procedures are the specific tasks performed by an auditor to obtain sufficient appropriate audit evidence to form an opinion on the subject matter.
- Evidence must be sufficient (quantity) and appropriate (quality/relevance).
- Methods include inquiry, observation, inspection, recalculation, re-performance, and analytical procedures.
- Documentation of procedures and evidence is critical.
Memory trick: Inspect, Observe, Inquire: IOI for evidence.