IS 監査人がフォローアップ監査を実施し、監査対象者が発見事項を修正するために取ったアプローチが、前回の監査で確認された合意済みのアプローチと異なることを知りました。監査人が次に取るべき行動は次のどれですか。
正解:A
The auditor's next course of action should be to evaluate the appropriateness of the remedial action taken by the auditee. The auditor should assess whether the alternative approach taken by the auditee is effective, efficient, and aligned with the audit objectives and recommendations. The auditor should also consider the impact of the change on the audit scope, criteria, and risk assessment. Conducting a risk analysis incorporating the change, reporting results of the follow-up to the audit committee, and informing senior management of the change in approach are possible subsequent actions that the auditor may take after evaluating the appropriateness of the remedial action taken. References: CISA Review Manual (Digital Version): Chapter 1 - Information Systems Auditing Process