ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is evaluating an organization's compliance with its internal security policies and relevant industry regulations. During the audit, the auditor discovers that the organization's incident response plan has not been updated in over two years, despite significant changes in the IT infrastructure and threat landscape. Which of the following is the MOST appropriate action for the IS auditor to take?

  1. ADiscuss the issue informally with the IT manager to understand the reasons for the delay.
  2. BExpand the scope of the audit to include a detailed review of all security documentation.
  3. CRecommend an immediate re-evaluation and update of the incident response plan.
  4. DDocument the finding and assess the potential impact on the organization's security posture.
Show answer & explanation

Correct answer: D. Document the finding and assess the potential impact on the organization's security posture.

The IS auditor's primary role is to document findings and assess their impact. Recommending immediate actions or expanding scope without full assessment is premature. Informal discussions are not a formal audit step.

Why the other options are wrong

  • A. Informal discussions are not a formal audit procedure and do not ensure proper documentation or follow-up.
  • B. Expanding the audit scope should be a decision based on the significance of documented findings, not an immediate reaction to one discovery.
  • C. While a good outcome, recommending immediate action is premature before fully documenting and assessing the finding's impact.

Audit Finding Documentation

The formal process of recording identified control weaknesses, non-compliance, or deviations from established standards, along with their potential impact.

  • Ensures clear communication of issues.
  • Provides evidence for recommendations.
  • Forms the basis for management response.

Memory trick: Audit findings are like puzzle pieces; first, you find them, then you see their place in the big picture.

More Domain 1: Information System Auditing Process questions