ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

An IS auditor is preparing for a follow-up audit to verify the implementation of corrective actions for several high-risk findings identified in a previous audit. The original audit report recommended the implementation of multi-factor authentication (MFA) for all remote access. Management has informed the auditor that they have implemented a new strong password policy instead, citing cost and complexity as reasons for not implementing MFA. What is the auditor's MOST appropriate immediate response?

  1. ADocument management's decision and assess whether the alternative control adequately mitigates the original risk.
  2. BEscalate the issue immediately to the audit committee as management has failed to implement the recommended control.
  3. CAccept the strong password policy as an alternative, provided it is well-implemented and monitored.
  4. DInsist that management implement MFA as originally recommended, as it is the most effective control.
Show answer & explanation

Correct answer: A. Document management's decision and assess whether the alternative control adequately mitigates the original risk.

The auditor's role is to verify that the identified risk has been adequately mitigated, not necessarily that the exact recommendation was followed. If management implements an alternative control, the auditor must assess if this alternative effectively addresses the original risk. Documenting and assessing is the correct immediate step.

Why the other options are wrong

  • B. Escalation is premature. The auditor first needs to assess if the alternative control is indeed insufficient to mitigate the risk before escalating.
  • C. Accepting the alternative without proper assessment would be a dereliction of duty; the auditor must verify its effectiveness.
  • D. Insisting on the original recommendation without assessing the alternative could be overly prescriptive and might not consider valid business constraints.

Follow-up Audit Objective

To verify that corrective actions have been effectively implemented and that the original risks identified in a prior audit have been adequately mitigated.

  • Focuses on risk mitigation, not just recommendation adherence.
  • Requires assessment of alternative controls.
  • Ensures ongoing control effectiveness.

Memory trick: Follow-up: 'Did the fix work, or is there a new path to safety?'

More Domain 1: Information System Auditing Process questions