ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is performing a follow-up audit on previously identified control weaknesses related to privileged user access. The original audit recommended implementing a robust privileged access management (PAM) solution. Which of the following is the MOST effective audit procedure to confirm the successful and sustained implementation of the PAM solution?

  1. AObtaining a management assertion letter confirming the PAM solution is in place.
  2. BInterviewing IT security managers about their satisfaction with the new PAM system.
  3. CExamining system logs to verify PAM solution activity and sampling privileged sessions for review.
  4. DReviewing the project plan and vendor invoices for the PAM solution.
Show answer & explanation

Correct answer: C. Examining system logs to verify PAM solution activity and sampling privileged sessions for review.

Examining system logs provides objective evidence of the PAM solution's operational activity. Sampling privileged sessions for review directly verifies that the solution is not only implemented but also effectively controlling and monitoring privileged access as intended.

Why the other options are wrong

  • A. A management assertion letter is a representation, not independent audit evidence of actual operation.
  • B. Interviews provide subjective evidence and do not confirm actual operation or effectiveness.
  • D. Project plans and invoices confirm purchase and deployment, not operational effectiveness.

Follow-up Audit Effectiveness

Follow-up audits assess whether management has taken appropriate, timely, and effective corrective actions in response to previously reported audit findings and recommendations.

  • Verifies implementation and effectiveness of controls.
  • Ensures risks are mitigated as intended.
  • Contributes to continuous improvement of the control environment.

Memory trick: Verify, Validate, Re-evaluate: VVR for follow-up.

More Domain 1: Information System Auditing Process questions