ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy
An IS auditor is reviewing an organization's patch management process. The auditor finds that critical security patches are consistently delayed for production systems, citing concerns about system instability. This directly increases which type of risk?
- AAudit risk
- BControl risk
- CDetection risk
- DInherent risk
Show answer & explanationAnswer & explanation
Correct answer: B. Control risk
Control risk is the risk that a material misstatement will not be prevented or detected on a timely basis by the entity's internal controls. Consistently delayed patches indicate a weakness in the control process designed to mitigate vulnerabilities, thereby increasing control risk.
Why the other options are wrong
- A. Audit risk is the overall risk of the auditor issuing an inappropriate opinion, which is a combination of inherent, control, and detection risks.
- C. Detection risk relates to the auditor's procedures failing to detect misstatements, not the organization's internal processes.
- D. Inherent risk is the susceptibility to misstatement before considering controls. While vulnerabilities exist, the failure to patch them is a control issue.
Control Risk
Control risk is the risk that a material misstatement that could occur in an assertion will not be prevented or detected and corrected on a timely basis by the entity’s internal control.
- Related to the effectiveness of internal controls.
- Higher when controls are weak or non-existent.
- Can be influenced by the auditor's assessment of controls.
Memory trick: Inherent, Control, Detection: ICD for Audit Risk.