exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 594 discussion

Actual exam question from Isaca's CISA
Question #: 594
Topic #: 1
[All CISA Questions]

An IS auditor is assigned to review the IS department's quality procedures. Upon contacting the IS manager, the auditor finds that there is an informal unwritten set of standards. Which of the following should be the auditor's NEXT action?

  • A. Finalize the audit and report the finding.
  • B. Document and test compliance with the informal standards.
  • C. Postpone the audit until IS management implements written standards.
  • D. Make recommendations to IS management as to appropriate quality standards.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
9967be3
1 week, 2 days ago
Selected Answer: B
Can not be D beacuse first, the auditor must understand the current state.
upvoted 1 times
...
Infysenthil
10 months ago
My thought : Option B - Next course of action. Option D - Best course of action.
upvoted 3 times
...
a84n
1 year ago
Selected Answer: B
Answer B informal unwritten standards are accepted and that's why IS auditor will document them in the report and test the compliance against it
upvoted 3 times
...
takuanism
1 year, 3 months ago
Selected Answer: A
Does it accept IS Auditor makes an operational document by auditor himself? I think this answer is A, the auditor should report the facts first.
upvoted 1 times
...
FAGFUR
1 year, 5 months ago
Selected Answer: D
The lack of formal written standards raises concerns about consistency, repeatability, and clarity in the quality procedures. The auditor should communicate this finding to IS management and recommend the establishment of appropriate, documented quality standards. This ensures that expectations are clearly defined, understood, and followed, contributing to a more effective and efficient IS environment.
upvoted 2 times
...
3008
1 year, 11 months ago
Selected Answer: D
Documenting and testing compliance with the informal standards (option B) would be a possible action but it would not address the issue of the lack of formal quality procedures. The auditor's role is to provide recommendations for improvement, rather than just test compliance. Therefore, the best course of action is to make recommendations to IS management as to appropriate quality standards (option D). The auditor can provide guidance on industry best practices or established standards such as ISO 9001 or ITIL, which the organization can adopt and document in their procedures. This will help ensure that the quality procedures are consistent and followed consistently across the organization.
upvoted 3 times
...
BabaP
1 year, 12 months ago
Selected Answer: D
D is better
upvoted 1 times
BabaP
1 year, 12 months ago
Not sure, please delete
upvoted 1 times
...
...
saado9
2 years ago
D. Make recommendations to IS management as to appropriate quality standards.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago