IS 監査人が IS 部門の品質手順を確認するよう任命されています。監査人が IS マネージャーに連絡したところ、非公式で暗黙の標準があることが分かりました。監査人が次にとるべきアクションは次のどれですか 1?
正解:C
The auditor's next action after finding that there is an informal unwritten set of standards in the IS department is to document and test compliance with the informal standards. This is because the auditor's role is to evaluate the adequacy and effectiveness of the existing controls, regardless of whether they are formal or informal, written or unwritten. The auditor should also assess the risks and implications of having informal standards, such as lack of consistency, accountability, or traceability. The auditor should not make recommendations, postpone the audit, or finalize the audit without performing the audit procedures.
References:
* CISA Review Manual (Digital Version), Chapter 2, Section 2.21
* CISA Online Review Course, Domain 1, Module 1, Lesson 12