ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is preparing to conduct an audit of an organization's new cloud-based customer relationship management (CRM) system. Management has expressed concerns about the security of customer data hosted by the third-party cloud provider. Which of the following is the MOST important step for the IS auditor to perform first?

  1. APerform vulnerability scans on the organization's network perimeter.
  2. BObtain and review the cloud provider's Service Organization Control (SOC) 2 report.
  3. CInterview key CRM system users to understand their data access requirements.
  4. DDevelop a detailed test plan for the CRM system's application controls.
Show answer & explanation

Correct answer: B. Obtain and review the cloud provider's Service Organization Control (SOC) 2 report.

Before developing detailed test plans or interviewing users, the IS auditor must first understand the controls in place at the third-party cloud provider. A SOC 2 report provides assurance regarding these controls, which is crucial given management's security concerns about customer data.

Why the other options are wrong

  • A. Performing vulnerability scans on the organization's perimeter is relevant for the organization's own infrastructure, but not for the cloud provider's hosted environment.
  • C. Interviewing users is a valuable step for understanding business processes and access needs, but it doesn't address the primary concern about the cloud provider's security.
  • D. Developing a detailed test plan for application controls is important but should follow an understanding of the third-party's controls.

Third-Party Assurance (SOC Reports)

Service Organization Control (SOC) reports provide an independent auditor's opinion on controls at a service organization relevant to user entities' internal control over financial reporting (SOC 1) or security, availability, processing integrity, confidentiality, or privacy (SOC 2).

  • SOC 2 reports specifically address security, availability, processing integrity, confidentiality, and privacy.
  • Essential for auditing cloud providers or any third-party handling sensitive data.
  • Helps IS auditors assess control effectiveness without directly auditing the third party.

Memory trick: Cloud Security Needs SOC Proof First!

More Domain 1: Information System Auditing Process questions