712-50 Question 64
Single answerA newly appointed CCISO is reviewing the results of an internal audit of the organization's identity and access management (IAM) controls for a regulated business unit. The audit was performed using the company's approved methodology aligned to risk-based auditing principles and mapped to defined control criteria from internal policy, regulatory requirements, and a recognized control framework. The audit report notes that quarterly access reviews were completed for only 55% of in-scope systems, several terminated employees retained active accounts for more than 30 days, and compensating detective controls were inconsistent across business applications. Business leaders argue that no confirmed fraud or breach has occurred and request that the findings be downgraded to avoid delaying a major product launch. What should the CCISO do FIRST to ensure the audit results are interpreted appropriately against established criteria and organizational objectives?
- A
Reclassify the findings as low risk because there is no evidence of an actual security incident or financial loss
- B
Validate the findings against the pre-established audit criteria, assess the control deficiencies in terms of residual risk and business impact, and present the results to governance stakeholders for risk-based decision-making
- C
Postpone reporting the audit results until additional technical testing can prove whether the access control weaknesses were exploited
- D
Accept management's request to downgrade the findings if they commit to remediating the issues after the product launch
Show answer and explanation
Correct answer: B
Explanation
The best answer is to validate and interpret the audit results against the agreed audit criteria, then communicate the resulting risk in business terms to the proper governance body. In a CCISO context, the executive role is not to suppress or soften findings for operational convenience, but to preserve the integrity of the audit process and support informed risk decisions. Established audit standards and best practices emphasize that audit conclusions should be evidence-based, criteria-driven, and communicated in a timely manner. This is consistent with principles found in IS audit practice guidance, internal control frameworks such as COSO, and control evaluation approaches used in frameworks like COBIT and ISO/IEC 27001-related assurance activities. The absence of a known incident does not negate a deficiency in preventive and detective controls, especially where access review failures and delayed deprovisioning increase residual risk, compliance exposure, and the likelihood of unauthorized access. Governance stakeholders may choose to accept, mitigate, transfer, or avoid the risk, but that decision must be made transparently after objective reporting of the audit results.
- A. Incorrect.
Incorrect. Audit results are evaluated against defined criteria, not only against evidence of realized harm. A lack of confirmed fraud or breach does not invalidate a control failure. This option reflects a common misconception that only exploited weaknesses matter, whereas audit conclusions must consider design and operating effectiveness of controls and the resulting exposure.
- B. Correct.
Correct. The CCISO should ensure the audit findings are interpreted against the approved criteria used in the audit, then translate those deficiencies into residual risk, compliance exposure, and business impact for governance review. This aligns with risk-based auditing and executive accountability: management may accept risk, but only after clear, objective reporting based on established standards and criteria.
- C. Incorrect.
Incorrect. Audit reporting should not be delayed simply because exploitation has not been demonstrated. Audits assess whether controls are adequate and operating effectively, not whether an incident has already occurred. Additional testing may be useful in some cases, but postponing communication of known control gaps undermines timely governance and risk treatment.
- D. Incorrect.
Incorrect. The CCISO should not unilaterally downgrade valid findings to accommodate delivery pressure. Management can propose remediation timelines or formally accept risk through the appropriate governance process, but the integrity of the audit result must remain tied to the evidence and defined assessment criteria. This option represents a governance failure and weak tone from leadership.