712-50 Question 60
Single answerUnderstand the IT audit process and be familiar with IT audit standardsA newly appointed CISO is preparing for an external IT audit of a global manufacturing company. Internal reviews have shown inconsistent evidence collection, duplicate testing by different teams, and tension between the security team and internal audit over who should validate access controls in the ERP environment. The audit committee has asked the CISO to improve readiness for the upcoming audit while aligning with recognized IT audit standards and preserving audit independence. Which action should the CISO take FIRST to most effectively address these concerns?
- A
Establish a risk-based audit coordination process that maps key controls to business risks, defines ownership for evidence preparation, and confirms that control testing remains independent from control operation
- B
Direct the security operations team to perform a full pre-audit of all ERP controls and submit the results to the external auditors as the primary source of assurance
- C
Ask the external auditors to adopt the security team's existing control checklist so that all parties use the same testing script and reduce duplicate effort
- D
Require internal audit to stop reviewing ERP access controls because the security team has greater technical expertise and can assess those controls more efficiently
Show answer and explanation
Correct answer: A
Explanation
The most appropriate first step is to create a structured, risk-based audit coordination process that clarifies responsibilities without undermining independence. In practice, this means identifying in-scope systems and risks, mapping key controls to those risks, assigning control and evidence owners, standardizing evidence collection, and agreeing on how internal audit, security, and external auditors will coordinate to reduce unnecessary duplication. This reflects established best practices from ISACA's risk-based IT audit approach, the Institute of Internal Auditors' International Standards for the Professional Practice of Internal Auditing, and general governance principles such as segregation of duties and independent assurance. A CISO should facilitate readiness and control transparency, but should not replace independent audit functions. Management can support audits through self-assessments and documentation preparation, yet formal assurance activities must remain sufficiently independent to be credible to auditors, regulators, and the audit committee.
- A. Correct.
This is the best first action because it addresses all three stated problems: inconsistent evidence, duplicate testing, and uncertainty over responsibilities. A risk-based audit coordination process aligns with widely accepted audit practices, including risk-focused planning found in ISACA IT audit guidance and IIA standards. Mapping controls to business risks improves relevance and scoping, defining evidence ownership improves readiness, and preserving independent control testing addresses a core audit principle: those who operate controls should not be the sole party validating their effectiveness.
- B. Incorrect.
This is incorrect because having the security operations team perform a full pre-audit of controls they may own or operate creates an independence problem. While self-assessments can help readiness, they should not be treated as the primary source of assurance for formal audit purposes. Auditors may consider management testing, but they still require independent evaluation before relying on it.
- C. Incorrect.
This is incorrect because external auditors must retain control over their methodology and testing approach to comply with professional standards and maintain independence. Coordination is useful, but asking them to adopt management's checklist as their primary testing script could impair objectivity and may not meet their audit objectives or materiality thresholds.
- D. Incorrect.
This is incorrect because technical expertise does not replace the need for independent assurance. Internal audit's role is to provide independent, objective assurance to management and the board. Removing internal audit from ERP access control review because security is more technically skilled confuses the first and third lines of responsibility and weakens governance.