ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy
During the planning phase of an information systems audit, an IS auditor identifies that the organization recently experienced a significant data breach due to a misconfigured firewall. This event would primarily impact the auditor's assessment of which of the following?
- AAudit scope
- BInherent risk
- CControl risk
- DDetection risk
Show answer & explanationAnswer & explanation
Correct answer: B. Inherent risk
A recent significant data breach indicates a higher susceptibility of the organization's information systems to material misstatement or errors, before considering the effectiveness of internal controls. This directly relates to inherent risk.
Why the other options are wrong
- A. Audit scope defines the boundaries of the audit, not directly impacted by a breach in this context.
- C. Control risk is the risk that a material misstatement will not be prevented or detected by internal controls. While the breach suggests control weaknesses, the initial assessment before control evaluation is inherent risk.
- D. Detection risk is the risk that the IS auditor's procedures will not detect a material misstatement. This is related to the auditor's work, not the organization's prior events.
Inherent Risk
Inherent risk is the susceptibility of an assertion about a class of transaction, account balance, or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls.
- Exists independently of the audit.
- Related to the nature of the business or transaction.
- Higher for complex or unusual transactions.
Memory trick: Inherent, Control, Detection: ICD for Audit Risk.