An IS auditor believes that management has accepted a level of residual risk that is not appropriate for the organization. Which of the following is the auditor's MOST appropriate course of action?
Correct Answer: B
The correct answer is B. Discuss the matter with IS audit management and executive management. Residual risk is the risk remaining after management has implemented a risk response. Risk acceptance must be made within the organization's risk appetite and risk tolerance. ISACA defines risk acceptance as a decision to accept risk according to the risk appetite and tolerance set by senior management, where the enterprise can assume the risk and absorb any losses. If the IS auditor believes management accepted a risk level that is not appropriate, the auditor should not ignore the issue or simply document it without further discussion. The appropriate first step is to discuss the matter with IS audit management and executive management. This gives the organization an opportunity to reassess the decision, confirm whether the risk is within appetite, and determine whether additional treatment is required. Option A may become appropriate later if executive management continues to accept a risk that exceeds risk appetite. ISACA guidance on follow-up activities states that when accepted risk is greater than the enterprise' s risk appetite, it should be discussed with senior management and brought to the attention of the audit committee or board if necessary. Option C is incorrect because taking no further action would be inappropriate when the auditor believes the accepted residual risk is excessive. Option D is also incorrect because the audit report should fairly represent management's response, including risk acceptance, rather than omitting it. This question maps to Information Systems Auditing Process because it concerns audit judgment, communication of audit findings, escalation, and reporting. References: ISACA CISA Exam Content Outline, Domain 1; ISACA Interactive Glossary, "Residual risk," "Risk acceptance," and "Risk appetite"; ISACA guidance on audit follow-up activities.
Question 287
An IS auditor is reviewing the installation of a new server. The IS auditor's PRIMARY objective is to ensure that
Correct Answer: D
Question 288
During the requirements definition phase of a software development project, the aspects of software testing that should be addressed are developing:
Correct Answer: D
Explanation/Reference: Explanation: A key objective in any software development project is to ensure that the developed software will meet the business objectives and the requirements of the user. The users should be involved in the requirements definition phase of a development project and user acceptance test specification should be developed during this phase. The other choices are generally performed during the system testing phase.
Question 289
In an EDI process, the device which transmits and receives electronic documents is the:
Correct Answer: A
Section: Protection of Information Assets Explanation: A communications handler transmits and receives electronic documents between trading partners and/or wide area networks (WANs).
Question 290
Which of the following is MOST important to consider when reviewing an organization's defined data backup and restoration procedures?
Correct Answer: B
The recovery point objective (RPO) is the maximum amount of time that can elapse between the last successful backup and the time of restoration in the event of a data loss incident. When reviewing an organization's defined data backup and restoration procedures, it is important to consider the RPO to ensure that the organization is able to restore data up to the most recent successful backup.