年次内部監査計画の策定に携わっている情報システム監査人は、最高情報責任者 (CIO) が、前年度の多数の推奨事項に対処するためにさらに時間が必要であるため、翌年度は情報システム監査を行わないよう要求していることを知ります。監査人が最初に行うべきことは、次のどれですか。
正解:A
The auditor should first escalate to audit management to discuss the audit plan. This is because the audit plan should be based on a risk assessment and aligned with the organization's objectives and strategies. The auditor should not accept the CIO's request without proper justification and approval from the audit management, who are responsible for ensuring the audit plan's quality and independence. The auditor should also communicate the potential risks and implications of not conducting IS audits in the upcoming year, such as missing new or emerging threats, vulnerabilities, or compliance issues. References:
* CISA Review Manual (Digital Version), Chapter 2, Section 2.11
* CISA Online Review Course, Domain 1, Module 1, Lesson 22