プロジェクトチームは、既存のビジネスアプリケーションの代替品を開発するために、アジャイルアプローチに切り替えることを決定しました。保護監査の有効性を確保するために、情報システム監査人が最初に行うべきことは次のうちどれですか?
正解:C
Explanation
Understanding the specific agile methodology that will be followed is the first step that an IS auditor should do to ensure the effectiveness of the project audit. An IS auditor should familiarize themselves with the agile approach, principles, practices, and tools that will be used by the project team, as well as the roles and responsibilities of the project stakeholders. This will help the IS auditor to identify and assess the relevant risks and controls for the project audit. The other options are not the first steps that an IS auditor should do, but rather possible subsequent actions that may depend on the specific agile methodology. References:
CISA Review Manual (Digital Version), Chapter 4, Section 4.3.21
CISA Review Questions, Answers & Explanations Database, Question ID 211