ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

An IS auditor is reviewing an organization's vendor management process for critical IT service providers. The organization relies on a third-party for its core financial processing system. Which of the following audit procedures would provide the MOST assurance regarding the security and control environment of the third-party provider?

  1. AInterviewing the organization's vendor relationship manager about the vendor's performance.
  2. BReviewing the service level agreement (SLA) to ensure it includes security clauses.
  3. CPerforming an on-site audit of the third-party provider's data center.
  4. DObtaining and reviewing the third-party provider's System and Organization Controls (SOC 2) report.
Show answer & explanation

Correct answer: D. Obtaining and reviewing the third-party provider's System and Organization Controls (SOC 2) report.

A SOC 2 report (Type 2) provides an independent auditor's opinion on the design and operating effectiveness of the third-party service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a period of time. This provides the most comprehensive and objective assurance without the need for the IS auditor to directly audit the third-party.

Why the other options are wrong

  • A. Interviews provide subjective information and are not sufficient to assess the control environment of a third-party.
  • B. An SLA outlines expectations but does not provide independent assurance of actual control effectiveness.
  • C. Performing an on-site audit of a third-party is often not feasible, costly, and typically not permitted by contract. A SOC 2 report is designed to address this need for assurance.

Third-Party Assurance (SOC Reports)

System and Organization Controls (SOC) reports are independent audit reports that provide information about the controls at a service organization relevant to user entities' internal control over financial reporting (SOC 1) or security, availability, processing integrity, confidentiality, or privacy (SOC 2).

  • SOC 2 reports are for non-financial reporting controls (e.g., security).
  • Type 2 reports cover operating effectiveness over a period.
  • Provides independent assurance, reducing need for direct audits.

Memory trick: Trust the SOC: Service Organizations Certify Controls.

More Domain 1: Information System Auditing Process questions